PT-2016-4778 · Cisco · Cisco Ios Xr+1
Publicado
2016-07-13
·
Atualizado
2017-09-01
·
CVE-2016-1426
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR versions 5.x through 5.2.5
Description
A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform. The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device.
Recommendations
For Cisco IOS XR versions 5.x through 5.2.5, update to a fixed software version to address this vulnerability. As a temporary workaround, consider restricting the number of SSH, SCP, and SFTP management connections to the affected device until a patch is available.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios Xr
Ncs 6000