Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly handle Online Certificate Status Protocol (OCSP) connection failures, which allows remote OCSP responders to cause a denial of service (TCP socket exhaustion) by rejecting connection attempts, aka Bug ID CSCsz36816.
https://exchange.xforce.ibmcloud.com/vulnerabilities/64605
http://www.securitytracker.com/id?1024963
http://www.securityfocus.com/bid/45767
http://www.cisco.com/en/US/docs/security/asa/asa82/release/notes/asarn82.pdf