PT-2015-7188 · Cisco · Cisco Asr 5000+1
Publicado
2015-10-16
·
Atualizado
2016-12-09
·
CVE-2015-6334
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045
Description
The issue allows remote attackers to cause a denial of service by restarting the vpnmgr process via a crafted header in a TACACS packet.
Recommendations
For Cisco ASR 5000 and 5500 devices with software 18.0.0.57828, update to a version that fixes the issue.
For Cisco ASR 5000 and 5500 devices with software 19.0.M0.61045, update to a version that fixes the issue.
As a temporary workaround, consider restricting access to TACACS packets to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Asr 5000
Cisco Asr 5500