CVE-2015-0676: Cisco Adaptive Security Appliance Software

High severity, CVSS 7.1. EPSS: 1.1% chance of exploitation in the next 30 days.

The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cause a denial of service (memory consumption or device outage) by triggering outbound DNS queries and then sending crafted responses to these queries, aka Bug ID CSCuq77655.

Affected products

  • Cisco Adaptive Security Appliance Software: version 7.0.1 only; version 7.0.1.4 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; version 7.0.4.2 only; …

Published 2015-04-13. Last modified 2026-06-17.