← Back

CVE-2015-0677

nvd nist
Published: Apr 13, 2015Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload) via a crafted XML document, aka Bug ID CSCus95290.

Affected (70)

1 product
Configuration A
70 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.4.1.11
Version 8.4.1.3
Version 8.4.1
Version 8.4.2.1
Version 8.4.2.8
Version 8.4.2
Version 8.4.3.8
Version 8.4.3.9
Version 8.4.3
Version 8.4.4.1
Version 8.4.4.3
Version 8.4.4.5
Version 8.4.4.9
Version 8.4.4
Version 8.4.5.6
Version 8.4.5
Version 8.4.6
Version 8.4.7.15
Version 8.4.7.22
Version 8.4.7.23
Version 8.4.7.26
Version 8.4.7.3
Version 8.4.7
Version 8.6.1.10
Version 8.6.1.12
Version 8.6.1.13
Version 8.6.1.14
Version 8.6.1.1
Version 8.6.1.2
Version 8.6.1.5
Version 8.6.1
Version 9.0.1
Version 9.0.2.10
Version 9.0.2
Version 9.0.3.6
Version 9.0.3.8
Version 9.0.3
Version 9.0.4.17
Version 9.0.4.1
Version 9.0.4.20
Version 9.0.4.24
Version 9.0.4.26
Version 9.0.4.29
Version 9.0.4.5
Version 9.0.4.7
Version 9.0.4
Version 9.1.1.4
Version 9.1.1
Version 9.1.2.8
Version 9.1.2
Version 9.1.3.2
Version 9.1.3
Version 9.1.4.5
Version 9.1.4
Version 9.1.5.10
Version 9.1.5.12
Version 9.1.5.15
Version 9.1.5.21
Version 9.1.5
Version 9.2.1
Version 9.2.2.4
Version 9.2.2.7
Version 9.2.2.8
Version 9.2.2
Version 9.2.3.3
Version 9.2.3
Version 9.3.1.1
Version 9.3.1
Version 9.3.2.2
Version 9.3.2

References (4)

Timeline

No history available yet.