Vulnerability Bulletins |
Cisco Adaptive Security Appliance Non-DCERPC Traffic Bypass Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in the Distributed Computing Environment/Remote Procedure Calls (DCERPC) Inspection feature of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to send traffic that is not DCERPC between hosts configured only for DCERPC inspection. The DCERPC traffic should be allowed only on TCP port 135.The vulnerability is due to an internal access control list (ACL), which is used to allow DCERPC traffic but is incorrectly programmed to allow all More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160111-asa?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Adaptive%20Security%20Appliance%20Non-DCERPC%20Traffic%20Bypass%20Vuln |
|






