PT-2016-4739 · Cisco · Cisco Prime Network Analysis Module
Publicado
2016-06-03
·
Atualizado
2017-09-02
·
CVE-2016-1370
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Network Analysis Module (NAM) versions prior to 6.2(1-b)
Description
The issue allows remote attackers to cause a denial of service, resulting in a process crash and monitoring outage, by sending crafted IPv6 packets. This is due to a miscalculation of IPv6 payload lengths.
Recommendations
For versions prior to 6.2(1-b), update to version 6.2(1-b) or later to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation via crafted IPv6 packets.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Prime Network Analysis Module