PT-2016-2113 · Cisco · Cisco Ios Xr

Publicado

2016-05-19

·

Atualizado

2016-12-01

·

CVE-2016-1407

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR versions 5.3.2 and earlier
Description The issue is due to improper handling of Local Packet Transport Services (LPTS) flow-base entries. This can cause too many known entries for a protocol to be created, leading to existing or new sessions being dropped. An attacker could exploit this by sending continuous connection attempts to open TCP ports, causing an exhaustion of services and resulting in a limited denial of service (DoS) condition.
Recommendations For Cisco IOS XR versions 5.3.2 and earlier, update to a version that addresses this issue, as software updates have been released by Cisco to fix the vulnerability. At the moment, there is no information about other workarounds that could mitigate this issue.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01466
CVE-2016-1407

Produtos afetados

Cisco Ios Xr