Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2008-2733

CVE information

Published

15 years ago

Last Modified

6 years ago

CVSSv2.0 Severity

High

Impact Analysis

Description

Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942..

CVSSv2.0 Score

Severity
High
Base Score
7.1/10
Exploit Score
8.6/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
None
Impact Score
6.9/10
Confidentiality Impact
None
Availability Impact
Complete
Integrity Impact
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:h:cisco:pix:8.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.1:*:*:*:*
  Yes
- -
cpe:2.3:h:cisco:pix:8.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.2:*:*:*:*
  Yes
- -
cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.0:*:*:*:*
  Yes
- -
cpe:2.3:h:cisco:pix:7.2:*:*:*:*:*:*:*
  Yes
- -