PT-2015-1031 · Cisco · Cisco Ios
Publicado
2015-03-25
·
Atualizado
2015-03-26
·
CVE-2015-0647
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.2 through 15.3
Description
The issue allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) UDP packets. Successful exploitation could allow an unauthenticated, remote attacker to cause a reload of the forwarding plane, resulting in an interruption of services on an affected device. Repeated exploitation could result in a sustained DoS condition. Additionally, it could cause a memory leak on an affected device.
Recommendations
For Cisco IOS versions 12.2 through 15.3, update to a version that includes the software updates released by Cisco to address these vulnerabilities.
As a temporary workaround, consider restricting the use of the CIP feature until a patch is available.
Avoid using crafted CIP packets to minimize the risk of exploitation.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios