漏洞信息详情
Cisco Adaptive Security Appliance Software和Cisco Firepower Threat Defense Software 资源管理错误漏洞
漏洞简介
Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software)都是美国思科(Cisco)公司的产品。Cisco Firepower Threat Defense是一套提供下一代防火墙服务的统一软件。Cisco Adaptive Security Appliances Software是一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。
Cisco Adaptive Security Appliance (ASA) Software和Cisco Firepower Threat Defense (FTD) Software中的IKEv2(英特网密钥交换协议2版本)功能存在资源管理错误漏洞,该漏洞源于该漏洞源于程序没有正确管理系统内存。攻击者可通过发送恶意的IKEv1流量利用该漏洞造成拒绝服务(系统内存资源耗尽)。以下产品及版本受到影响:Cisco Adaptive Security Virtual Appliance (ASAv);Firepower 2100 Series Appliances;Firepower Threat Defense Virtual (FTDv)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-ftd-ikev1-dos
参考网址
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3698.3/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cisco-ASA-denial-of-service-via-IKEv1-30506
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-ftd-ikev1-dos
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3698/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-15256
受影响实体
暂无
补丁
- Cisco Adaptive Security Appliance Software和Cisco Firepower Threat Defense Software 资源管理错误漏洞的修复措施<!--2019-10-2-->
还没有评论,来说两句吧...