CVE-2012-5415 describes a race condition vulnerability in Cisco Adaptive Security Appliances (ASA) devices, specifically affecting the 5500 series. This flaw allows remote attackers to trigger a denial of service (DoS) by establishing multiple connections, leading to excessive CPU consumption or device reloads due to improper handling of hash lookups for secondary flows. The vulnerability has a CVSS score of 5.4 (medium severity), indicating a network-based attack with high attack complexity and a complete impact on availability. While it can cause significant disruption, the technical difficulty of exploitation is considerable. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2CPE matchmatch criteria | cpe:2.3:h:cisco:5500_adaptive_security_appliance:7.2:2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:5500_series_adaptive_security_appliance:*:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:h:cisco:5500_series_adaptive_security_appliance:7.2:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.