The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adaptive_security_appliance_software | Cisco | 9.4.1 (including) | 9.4.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.4.1.1 (including) | 9.4.1.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.4.1.2 (including) | 9.4.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.4.1.3 (including) | 9.4.1.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.4.1.5 (including) | 9.4.1.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.4.2 (including) | 9.4.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.5.1 (including) | 9.5.1 (including) |