APP: Cisco Adaptive Security Appliance (ASA) Internet Key Exchange Buffer Overflow

This signature detects a vulnerability in Cisco Adaptive Security Appliance (ASA). Successful exploitation can allow remote code execution or denial of service.

Extended Description

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 devices, ASA 1000V devices, Adaptive Security Virtual Appliance (aka ASAv), Firepower 9300 ASA Security Module, and ISA 3000 devices allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via crafted UDP packets, aka Bug IDs CSCux29978 and CSCux42019.

Affected Products

Cisco adaptive_security_appliance_software

References

CVE: CVE-2016-1287

Short Name
APP:CISCO:ASA-IKE-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
(ASA) Adaptive Appliance Buffer CVE-2016-1287 Cisco Exchange Internet Key Overflow Security
Release Date
02/16/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3600
False Positive
Unknown
Vendors

Cisco

CVSS Score

10.0

Found a potential security threat?