cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
2
Replies

ASA 8.0.3 Vulnerable to TCP DOS Attacks?

stanleylam7_2
Level 1
Level 1

Can anyone confirm whether the ASA 8.0.3 image is affected by denial of service (DoS)       vulnerabilities that manipulate the state of Transmission Control  Protocol       (TCP) connections?

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee
2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

DOS to VPN on ASA is not affected on version 8.0.3:

http://www.cisco.com/en/US/products/products_security_advisory09186a0080833166.shtml

However, you might be affected by the following vulnerabilities:

http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml

Halijenn, thank you for confirming that 8.0.3 is not affected by the TCP DOS vulnerability.

I also looked at the other vulnerabilities listed in the other link.  We're currently using 8.0.3(19), so it looks like we're only concerned with SIP inspections which we do not have implemented.  Again, thank you for the heads up for providing the link.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card