Description
Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."
References (7)
Core 7
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080833166.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34023
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1636
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/23768
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25109
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/35333
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/337508
Scores
EPSS
0.0294
EPSS Percentile
85.7%
Details
Status
published
Products (4)
cisco/adaptive_security_appliance_software
7.1
cisco/adaptive_security_appliance_software
< 7.2.2
cisco/pix
7.1
cisco/pix
< 7.2
Published
May 02, 2007
Tracked Since
Feb 18, 2026