>> Cisco PIX and ASA Security Bypass and Denial of Service Vulnerabilities
Title : Cisco PIX and ASA Security Bypass and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2899 CVE ID : CVE-2008-3815 - CVE-2008-3816 - CVE-2008-3817 CWE ID : CWE-287 - CWE-399
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-23
Technical Description
Multiple vulnerabilities have been identified in Cisco PIX and ASA, which could be exploited by attackers to bypass security restrictions or cause a denial of service.
The first issue is caused by an unspecified error which could allow attackers to bypass VPN authentication and gain unauthorized access to appliances configured for IPSec or SSL-based remote access VPN and Windows NT Domain authentication.
The second vulnerability is caused by an error when processing malformed IPv6 packets, which could be exploited by attackers to cause a vulnerable applicance to reload, creating a denial of service condition.
The third issue is caused by a memory leak in the initialization code for the hardware crypto accelerator.