CVE-2016-9225
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of IP fragments. An attacker could exploit this vulnerability by sending crafted fragmented IP traffic across the CX module.
Leer descripción completaMostrar menos
An exploit could allow the attacker to exhaust free packet buffers in shared memory (SHM), causing the CX module to be unable to process further traffic, resulting in a DoS condition. This vulnerability affects all versions of the ASA CX Context-Aware Security module. Cisco has not released and will not release software updates that address this vulnerability. There are no workarounds that address this vulnerability. Cisco Bug IDs: CSCva62946.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.66%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-399
- CWE-399
Referencias
- http://www.securityfocus.com/bid/95788
- http://www.securitytracker.com/id/1037696
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-cas
- http://www.securityfocus.com/bid/95788
- http://www.securitytracker.com/id/1037696
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-cas
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-9225",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "n/a",
"product": "all versions of the ASA CX Context-Aware Security module",
"versions": [
{
"status": "affected",
"version": "all versions of the ASA CX Context-Aware Security module"
}
]
}
]
}
],
"published": "2017-02-01T19:59:00.157",
"references": [
{
"url": "http://www.securityfocus.com/bid/95788",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@cisco.com"
},
{
"url": "http://www.securitytracker.com/id/1037696",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-cas",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "http://www.securityfocus.com/bid/95788",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1037696",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-cas",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of IP fragments. An attacker could exploit this vulnerability by sending crafted fragmented IP traffic across the CX module. An exploit could allow the attacker to exhaust free packet buffers in shared memory (SHM), causing the CX module to be unable to process further traffic, resulting in a DoS condition. This vulnerability affects all versions of the ASA CX Context-Aware Security module. Cisco has not released and will not release software updates that address this vulnerability. There are no workarounds that address this vulnerability. Cisco Bug IDs: CSCva62946."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el manejador de fragmentos de IP de plano de datos del módulo CX Context-Aware Security de Cisco Adaptive Security Appliance (ASA) podrían permitir a un atacante remoto no autenticado provocar que el módulo CX no pudiera procesar más tráfico, resultando en una denegación de servicio (DoS). La vulnerabilidad se debe a un manejo inadecuado de fragmentos IP. Un atacante podría explotar esta vulnerabilidad mediante el envío de tráfico IP fragmentado manipulado a través del módulo CX. Un exploit podría permitir al atacante agotar los búfers de paquetes libres en la SHM, haciendo que el módulo CX no pueda procesar más tráfico, resultando en una condición DoS. Esta vulnerabilidad afecta a todas las versiones del módulo ASA CX Context-Aware Security. Cisco no ha lanzado y no lanzará actualizaciones de software que aborden esta vulnerabilidad. No existen soluciones provisionales que aborden esta vulnerabilidad. ID de errores de Cisco: CSCva62946"
}
],
"lastModified": "2026-06-17T00:55:42.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC9743A-641F-4F0A-97FC-5DF8B0333222"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1-40:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7F990CF-B6DD-4EE3-B45D-CE4B1110A6DB"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A81A0E90-9200-436C-81BC-FA4BF745EEDB"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.2-68:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13B6FFEA-4F46-4D20-9821-FE32B57F6145"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0_base:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8068EA1D-6AD6-4BF3-AA1F-C8AD0BC8F298"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.1.2-29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A4AE8C1-9BD1-491A-9835-D95F4D90F496"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.1.2-42:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0710827-10AD-4DE9-BB0F-B4D072DDC8DA"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.1.3-8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96F09A7A-9A3D-4D73-912A-2B01CEABEFBA"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.1.3-10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AA36AEA-6516-41DD-90D3-0504A4CB5231"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.1.3-13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68C47683-C68B-4B84-80F6-FDFF9156991C"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.2.1-1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEFA5ADA-E573-447B-AFD9-E37682B57BD9"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.2.2-1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5E0F299-9B0A-46A2-83A2-EEB3E6D2B828"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3\\(1.1.112\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EA695E3-7E4E-4ECA-8BF6-4B2024DA15D3"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.1-1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBAD7032-2FD8-4FAE-8A77-0488EE8ECAF3"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.2-1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5E3D601-FE3F-433A-84BD-6F070000BAE2"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.3.1-13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90ADCF2B-BD2C-48D3-9507-B0C82D6FDADA"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63B17493-3AD5-4699-A2D3-9F3B4BB3631C"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58C171D9-0EFF-43DC-AF02-D3B8A2DFACF2"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "055252B1-ABEA-4894-A84C-F9D75416346D"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9576E0A1-2184-4136-B161-D168FB7790A0"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A11720CA-D957-4F51-9388-3BE795E5D1C0"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4-6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A8EB3C3-7B09-4413-857A-0092FE1EB182"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3.4.1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEE236E6-BA43-47CD-BCE0-7BEFE9662B20"
},
{
"criteria": "cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.3_base:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D9B6425-12DD-44F4-9708-7D7529CB1DE5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}