PT-2016-1575 · Cisco · Cisco Ios

Publicado

2016-03-23

·

Atualizado

2022-07-28

·

CVE-2016-1347

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 15.1 through 15.5
Description The vulnerability in the Wide Area Application Services (WAAS) Express implementation allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment. This is due to insufficient validation of TCP segments. An attacker could exploit this vulnerability by routing a crafted TCP segment through an affected device, causing the device to reload. The WAAS Express feature must be enabled on the interface, typically a WAN interface, for the vulnerability to be exploited. In most deployments, this means crafted traffic must be initiated from within a device to exploit the vulnerability.
Recommendations For Cisco IOS versions 15.1 through 15.5, update to a newer version that includes the fix for this vulnerability. As a temporary workaround, consider disabling the WAAS Express feature on the WAN interface until a patch is available. Restrict access to the vulnerable interface to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00876
CVE-2016-1347

Produtos afetados

Cisco Ios