CVE-2016-9225 describes a denial-of-service vulnerability in the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module, affecting all versions. The flaw stems from improper handling of IP fragments, allowing an unauthenticated, remote attacker to exhaust packet buffers by sending crafted fragmented IP traffic. This results in the CX module being unable to process further traffic, causing a DoS condition. The vulnerability carries a high CVSS score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating it can be exploited remotely with low complexity and no user interaction, leading to a complete loss of availability. Cisco has not and will not release patches or workarounds for this issue. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.1CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1:*:*:*:*:*:*:* | ||
9.0.1-40CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1-40:*:*:*:*:*:*:* | ||
9.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.2:*:*:*:*:*:*:* | ||
9.0.2-68CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.2-68:*:*:*:*:*:*:* | ||
9.0_baseCPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.