CVE-2010-0149
Cisco ASA 5500 and PIX 500 - Denial of Service via TCP Connection Exhaustion
Title source: llmDescription
Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.46), 8.0 before 8.0(4.38), 8.1 before 8.1(2.29), and 8.2 before 8.2(1.5); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (prevention of new connections) via crafted TCP segments during termination of the TCP connection that cause the connection to remain in CLOSEWAIT status, aka "TCP Connection Exhaustion Denial of Service Vulnerability."
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38275
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38618
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/62433
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56336
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38636
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023612
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0415
Scores
EPSS
0.0408
EPSS Percentile
89.7%
Details
Status
published
Products (6)
cisco/asa_5500
7.1
cisco/asa_5500
7.2
cisco/asa_5500
8.0
cisco/asa_5500
8.1
cisco/asa_5500
8.2
cisco/pix_500
Published
Feb 19, 2010
Tracked Since
Feb 18, 2026