PT-2016-7701 · Cisco · Cisco Ios Xr

Publicado

2016-12-07

·

Atualizado

2017-01-04

·

CVE-2016-9205

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software version 6.1.1.BASE
Description A vulnerability in the HTTP 2.0 request handling code could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of HTTP requests. An attacker could exploit this vulnerability by sending malicious HTTP 2.0 requests to the targeted system.
Recommendations For Cisco IOS XR Software version 6.1.1.BASE, update to version 6.1.2.6i.MGBL, 6.1.22.9i.MGBL, or 6.2.1.14i.MGBL to resolve the issue. As a temporary workaround, consider restricting access to the HTTP 2.0 request handling functionality until a patch is applied.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9205

Produtos afetados

Cisco Ios Xr