PT-2015-6452 · Cisco · Cisco Ios Xr
Publicado
2015-06-18
·
Atualizado
2016-12-28
·
CVE-2015-4195
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR version 5.1.1.K9SEC
Description
A denial of service condition can be caused by an authenticated, remote attacker via a crafted disconnect action within an SSH session. The vulnerability occurs due to an error when an SSH connection is disconnected from the affected device, causing the vty to become unreachable and resulting in further SSH or Telnet connections to fail. To exploit this issue, an attacker must first authenticate to the targeted device, which reduces the likelihood of a successful exploit.
Recommendations
For Cisco IOS XR version 5.1.1.K9SEC, update to a fixed software version to resolve the issue. As a temporary workaround, consider restricting SSH connections to minimize the risk of exploitation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios Xr