CVE-2007-2461
Last modified
CVE-2007-2461 is a vulnerability of currently unknown severity. The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multiple DHCP servers are used.. EPSS estimates a 4.37% chance of exploitation in the next 30 days.
Description
The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multiple DHCP servers are used.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Pix | 7.2 |
| Cisco | Adaptive Security Appliance Software | 7.2.2 |
References
- http://www.kb.cert.org/vuls/id/530057Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/530057Patch, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2461?
How severe is CVE-2007-2461?
How do I fix CVE-2007-2461?
Are you affected by CVE-2007-2461?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
