PT-2016-2270 · Cisco · Cisco Ios Xe
Publicado
2016-06-17
·
Atualizado
2016-06-20
·
CVE-2016-1432
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE versions 3.15S through 3.16S
Description
The issue is related to a denial of service caused by a NULL pointer dereference and card restart. This can be triggered by a crafted SNMP request. The vulnerability exists because the affected platform does not properly handle SNMP read requests for a specific object ID that is not supported by the platform, leading to an attempt to reference a pointer with a NULL value. An authenticated, remote attacker can exploit this by submitting a specific, valid SNMP request, causing the supervisor card to restart and resulting in a denial of service condition.
Recommendations
For Cisco IOS XE versions 3.15S through 3.16S, update to a newer version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability.
At the moment, there is no information about other workarounds that address this vulnerability.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios Xe