CVE-2008-2734

Cisco ASA 5500 7.2-8.1 DoS via Crafted SSL/HTTP Packet

Title source: llm
STIX 2.1

Description

Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or HTTP packet, aka Bug ID CSCso66472.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020812
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44868
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31730
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30998

Scores

EPSS 0.0284
EPSS Percentile 85.2%

Details

CWE
CWE-399
Status published
Products (2)
cisco/adaptive_security_appliance_5500 8.0
cisco/adaptive_security_appliance_5500 8.1
Published Sep 04, 2008
Tracked Since Feb 18, 2026