The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle timeout, which allows remote attackers to cause a denial of service (connection-table exhaustion) via crafted requests that use an inspected protocol, aka Bug ID CSCuh13899.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=30607 | vendor advisory |
http://www.securityfocus.com/bid/62068 | vdb entry third party advisory |
http://www.securitytracker.com/id/1028968 | vdb entry third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3463 | vendor advisory |