CVE-2016-1385: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209.
Affected products
- Cisco Adaptive Security Appliance Software: version 8.4.0 only; version 8.4.1 only; version 8.4.1.3 only; version 8.4.1.11 only; version 8.4.2 only; version 8.4.2.1 only; …
Published 2016-05-26. Last modified 2026-06-17.