PT-2010-4331 · Cisco · Cisco Ios
Publicado
2010-09-22
·
Atualizado
2010-09-24
·
CVE-2010-2836
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.4, 15.0, and 15.1
Description
A memory leak in the SSL VPN feature of Cisco IOS allows remote attackers to cause a denial of service by improperly disconnecting SSL sessions, leading to connections that remain in the CLOSE-WAIT state. This could result in a memory exhaustion condition, causing device reloads, the inability to service new TCP connections, and other denial of service conditions.
Recommendations
For Cisco IOS versions 12.4, 15.0, and 15.1, update to a version that includes the software updates released by Cisco to address this vulnerability. As a temporary workaround, consider disabling the HTTP port redirection feature in the SSL VPN configuration to mitigate this issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios