PT-2016-2113 · Cisco · Cisco Ios Xr
Publicado
2016-05-19
·
Atualizado
2016-12-01
·
CVE-2016-1407
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR versions 5.3.2 and earlier
Description
The issue is due to improper handling of Local Packet Transport Services (LPTS) flow-base entries. This can cause too many known entries for a protocol to be created, leading to existing or new sessions being dropped. An attacker could exploit this by sending continuous connection attempts to open TCP ports, causing an exhaustion of services and resulting in a limited denial of service (DoS) condition.
Recommendations
For Cisco IOS XR versions 5.3.2 and earlier, update to a version that addresses this issue, as software updates have been released by Cisco to fix the vulnerability.
At the moment, there is no information about other workarounds that could mitigate this issue.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios Xr