PT-2010-2340 · Cisco · Cisco Ios
Publicado
2010-03-24
·
Atualizado
2017-08-17
·
CVE-2010-0583
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.1 through 12.4
Cisco IOS versions 15.0M before 15.0(1)M1
Description
A memory leak in the H.323 implementation allows remote attackers to cause a denial of service via malformed H.323 packets. This issue may be exploited to consume memory and cause a device reload. Two vulnerabilities in the H.323 implementation may be exploited remotely to cause a denial of service condition on a device running a vulnerable version of Cisco IOS Software.
Recommendations
For Cisco IOS versions 12.1 through 12.4, consider disabling H.323 if it is not required, as there are no workarounds other than disabling the service.
For Cisco IOS versions 15.0M before 15.0(1)M1, consider disabling H.323 if it is not required, as there are no workarounds other than disabling the service.
Update to a version of Cisco IOS Software that addresses these vulnerabilities, as listed in the Cisco IOS Software Security Advisory.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios