PT-2013-2973 · Vmware+1 · Vmware Esxi+2

Publicado

2013-05-29

·

Atualizado

2013-05-30

·

CVE-2013-1210

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Nexus 1000V Virtual Ethernet Module (VEM) kernel driver for VMware ESXi (affected versions not specified)
Description A denial of service issue exists due to insufficient validation of STUN protocol packets, resulting in an out of bound array index access and a crash of the ESXi hypervisor, leading to a purple screen of death. This can be exploited by sending specially crafted STUN packets to a vulnerable VEM when STUN protocol debugging is enabled. The issue requires access to a trusted, internal network to send the crafted packets, limiting the possibility of a successful exploit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1210

Produtos afetados

Cisco Nexus
Cisco Nexus 1000V Virtual Ethernet Module (Vem) Kernel Driver
Vmware Esxi