The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
| Software | From | Fixed in |
|---|---|---|
| cisco / security_agent | 4.0.3 | 4.0.3.x |
| cisco / security_agent | 4.0.2 | 4.0.2.x |
| cisco / security_agent | 3 | 3.x |
| cisco / security_agent | 4.0 | 4.0.x |
| okena / stormwatch | 3.x | 3.x.x |
| cisco / security_agent | 4.0.1 | 4.0.1.x |