Cisco Bug: CSCuo19916 - ASA - Cut Through Proxy sends empty redirect w/ Virtual HTTP and Telnet
Last Modified
Nov 27, 2020
Products (2)
- Cisco Adaptive Security Appliance (ASA) Software
- Cisco Adaptive Security Appliance (ASA) Software
Known Affected Releases
8.4(7) 9.1(2)
Description (partial)
Symptom: When using cut-through-proxy, virtual http, and virtual telnet on an ASA, clients may receive 302 Moved responses for the redirect that contain no location. With some browsers (confirmed on IE9), this behavior causes the client to continuously reset and restart the connection which results in a DOS situation for the ASA and any associated syslogs servers due to thousands of connection builds/teardowns within very short period of time. Conditions: 1. Must be using cut-through-proxy on the ASA 2. Must have a virtual HTTP configured as the redirect destination IP in the authentication proxy ACL 3. Must also have virtual telnet configured on the ASA with the same IP as virtual HTTP
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Status
- Severity
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases