漏洞类别:Cisco漏洞等级:
漏洞信息
A vulnerability in the Cisco Adaptive Security Appliance (ASA) Software implementation of access control list (ACL) permit and deny filters for ICMP Echo Reply messages could allow an unauthenticated, remote attacker to bypass ACL configurations for an affected device. ICMP traffic that should be denied may instead be allowed through an affected device.
The vulnerability is due to the implementation of ACL-based filters for ICMP Echo Requests and the range of ICMP Echo Request subtypes.
漏洞危害
An attacker could exploit this vulnerability by sending ICMP Echo Request traffic to an affected device. A successful exploit could allow the attacker to bypass ACL configurations for the device, which could allow traffic that should be denied to instead be allowed through the device.
解决方案
Refer to Cisco ASA advisory cisco-sa-20160711-asa for updates and patch information.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
0day
文章评论