Vulnerability Bulletins

Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow Vulnerability

   
Affected software Cisco
 
A vulnerability in the Internet Key Exchange (IKE) version 1 (v1)and IKE version 2 (v2) code of Cisco ASA Software could allow an unauthenticated,remote attacker to cause a reload of the affected system or to remotelyexecute code. The vulnerability is due to a buffer overflow inthe affected code area. An attacker could exploit this vulnerability bysending crafted UDP packets to the affected system. An exploitcould allow the attacker to execute arbitrary code and obtain fullcontrol of the system

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20ASA%20Software%20IKEv1%20and%20IKEv2%20Buffer%20Overflow%20Vulnera