PT-2017-17202 · Cisco · Cisco Ucs C-Series Rack Servers
Publicado
2017-05-22
·
Atualizado
2017-07-08
·
CVE-2017-6633
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco UCS C-Series Rack Servers version 3.0(0.234)
Description
A vulnerability in the TCP throttling process could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to insufficient rate-limiting protection. An attacker could exploit this by sending a high rate of TCP SYN packets to a specific TCP listening port, causing it to stop accepting new connections.
Recommendations
For Cisco UCS C-Series Rack Servers version 3.0(0.234), consider implementing rate-limiting measures on TCP SYN packets to prevent excessive connection requests until a fix is available. As a temporary workaround, restrict access to specific TCP listening ports to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ucs C-Series Rack Servers