PT-2013-2973 · Vmware+1 · Vmware Esxi+2
Publicado
2013-05-29
·
Atualizado
2013-05-30
·
CVE-2013-1210
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 1000V Virtual Ethernet Module (VEM) kernel driver for VMware ESXi (affected versions not specified)
Description
A denial of service issue exists due to insufficient validation of STUN protocol packets, resulting in an out of bound array index access and a crash of the ESXi hypervisor, leading to a purple screen of death. This can be exploited by sending specially crafted STUN packets to a vulnerable VEM when STUN protocol debugging is enabled. The issue requires access to a trusted, internal network to send the crafted packets, limiting the possibility of a successful exploit.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Nexus
Cisco Nexus 1000V Virtual Ethernet Module (Vem) Kernel Driver
Vmware Esxi