vendor:
ASA
by:
prdelka
7,5
CVSS
HIGH
Etherleak
200
CWE
Product Name: ASA
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2003-0001
CPE: Unknown
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2003
CVE-2003-0001 ‘Etherleak’ exploit
Exploit for hosts which use a network device driver that pads ethernet frames with data which vary from one packet to another, likely taken from kernel memory, system memory allocated to the device driver, or a hardware buffer on its network interface card. Exploit uses scapy with either ICMP or ARP requests as this can trigger with either but ICMP can hit layer3 filtering rules. Using ARP the padding appears to leak only fixed constant values when exploited, ICMP leaks random bytes.
Mitigation:
Upgrade to ASA 8.4.4.6/8.2.5.32