PT-2016-4739 · Cisco · Cisco Prime Network Analysis Module

Publicado

2016-06-03

·

Atualizado

2017-09-02

·

CVE-2016-1370

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco Prime Network Analysis Module (NAM) versions prior to 6.2(1-b)
Description The issue allows remote attackers to cause a denial of service, resulting in a process crash and monitoring outage, by sending crafted IPv6 packets. This is due to a miscalculation of IPv6 payload lengths.
Recommendations For versions prior to 6.2(1-b), update to version 6.2(1-b) or later to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation via crafted IPv6 packets.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-1370

Produtos afetados

Cisco Prime Network Analysis Module