PT-2016-2270 · Cisco · Cisco Ios Xe

Publicado

2016-06-17

·

Atualizado

2016-06-20

·

CVE-2016-1432

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE versions 3.15S through 3.16S
Description The issue is related to a denial of service caused by a NULL pointer dereference and card restart. This can be triggered by a crafted SNMP request. The vulnerability exists because the affected platform does not properly handle SNMP read requests for a specific object ID that is not supported by the platform, leading to an attempt to reference a pointer with a NULL value. An authenticated, remote attacker can exploit this by submitting a specific, valid SNMP request, causing the supervisor card to restart and resulting in a denial of service condition.
Recommendations For Cisco IOS XE versions 3.15S through 3.16S, update to a newer version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability. At the moment, there is no information about other workarounds that address this vulnerability.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01634
CVE-2016-1432

Produtos afetados

Cisco Ios Xe