
====================================================================

                                CERT-Renater

                   Note d'Information No. 2016/VULN178
_____________________________________________________________________

DATE                : 21/04/2016

HARDWARE PLATFORM(S): Cisco Adaptive Security Appliance.

OPERATING SYSTEM(S): Cisco Adaptive Security Appliance Software.

======================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-asa-dhcpv6
____________________________________________________________________

Cisco Security Advisory: Cisco Adaptive Security Appliance Software
DHCPv6 Relay Denial of Service Vulnerability

Advisory ID: cisco-sa-20160420-asa-dhcpv6

Revision 1.0

For Public Release 2016 April 20 16:00  GMT (UTC)

+---------------------------------------------------------------------

Summary
=======

A vulnerability in the DHCPv6 relay feature of Cisco Adaptive Security
Appliance (ASA) Software could allow an unauthenticated, remote
attacker to cause an affected device to reload.

The vulnerability is due to insufficient validation of DHCPv6 packets.
An attacker could exploit this vulnerability by sending crafted DHCPv6
packets to an affected device, resulting in a denial of service (DoS)
condition.

This vulnerability affects systems configured in routed firewall mode
and in single or multiple context mode. Cisco ASA Software is affected
by this vulnerability only if the software is configured with the
DHCPv6 relay feature. The vulnerability is triggered only by IPv6
traffic.

This vulnerability affects Cisco ASA Software release 9.4.1 only.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-asa-dhcpv6


==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================





