CVE-2008-2733
Last modified
CVE-2008-2733 is a vulnerability of currently unknown severity. Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.. EPSS estimates a 3.19% chance of exploitation in the next 30 days.
Description
Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance 5500 | 7.2 |
| Cisco | Adaptive Security Appliance 5500 | 8.0 |
| Cisco | Adaptive Security Appliance 5500 | 8.1 |
| Cisco | Pix | 7.2 |
| Cisco | Pix | 8.0 |
| Cisco | Pix | 8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2733?
How severe is CVE-2008-2733?
How do I fix CVE-2008-2733?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2726Integer overflow in the (1) rb_ary_splice function in Ruby 1…
- CVE-2008-2727Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-2728Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-2729arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.1…
- CVE-2008-2730The Real-Time Information Server (RIS) Data Collector servic…
- CVE-2008-2732Multiple unspecified vulnerabilities in the SIP inspection f…
- CVE-2008-2734Memory leak in the crypto functionality in Cisco Adaptive Se…
- CVE-2008-2735The HTTP server in Cisco Adaptive Security Appliance (ASA) 5…
- CVE-2008-2736Unspecified vulnerability in Cisco Adaptive Security Applian…
- CVE-2008-2737Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-2739The SERVICE.DNS signature engine in the Intrusion Prevention…
- CVE-2008-2742Unrestricted file upload in the mcpuk file editor (atk/attri…
Are you affected by CVE-2008-2733?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
