CVE-2010-0149 describes an unspecified vulnerability in Cisco ASA 5500 Series and PIX 500 Series Security Appliances that allows remote attackers to cause a denial of service. By sending crafted TCP segments during connection termination, an attacker can force connections into a CLOSE_WAIT state, leading to TCP connection exhaustion and preventing new connections. This vulnerability has a CVSS score of 7.8, indicating a high severity with a network-based attack vector, low attack complexity, and complete availability impact. There is no evidence of active exploitation, nor is public exploit code available in Metasploit or ExploitDB, and it has received no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:h:cisco:asa_5500:7.1:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:h:cisco:asa_5500:7.2:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:h:cisco:asa_5500:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:h:cisco:asa_5500:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:h:cisco:asa_5500:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.