CVE-2015-0678 describes a denial-of-service vulnerability in the virtualization layer of Cisco ASA FirePOWER Software (before 5.3.1.2 and 5.4.0.1) and ASA Context-Aware (CX) Software (before 9.3.2.1-9). An unauthenticated remote attacker can trigger a device reload by sending a rapid flood of crafted packets to the management interface. This vulnerability has a CVSS score of 7.8 (High), indicating a critical impact on availability with low attack complexity and no authentication required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.3.1CPE matchmatch criteria | cpe:2.3:o:cisco:asa_with_firepower_services:5.3.1:*:*:*:*:*:*:* | ||
5.3.1.1CPE matchmatch criteria | cpe:2.3:o:cisco:asa_with_firepower_services:5.3.1.1:*:*:*:*:*:*:* | ||
5.4.0CPE matchmatch criteria | cpe:2.3:o:cisco:asa_with_firepower_services:5.4.0:*:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1:*:*:*:*:*:*:* | ||
9.0.1-40CPE matchmatch criteria | cpe:2.3:o:cisco:asa_cx_context-aware_security_software:9.0.1-40:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.