PT-2017-3051 · Schneider Electric · Cisco Connected Grid Network Management System+1

Publicado

2017-09-06

·

Atualizado

2019-10-09

·

CVE-2017-6780

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Connected Grid Network Management System versions prior to IoT-FND Release 4.0 IoT Field Network Director versions prior to IoT-FND Release 4.0
Description A vulnerability in the TCP throttling process could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart. This is due to insufficient rate-limiting protection. An attacker could exploit this by sending a high rate of TCP packets to a specific group of open listening ports on a targeted device, allowing them to cause the system to consume additional memory. If enough available memory is consumed, the system will restart, creating a temporary denial of service (DoS) condition. The DoS condition will end after the device has finished the restart process.
Recommendations For Connected Grid Network Management System versions prior to IoT-FND Release 4.0, update to IoT-FND Release 4.0 or later to resolve the issue. For IoT Field Network Director versions prior to IoT-FND Release 4.0, update to IoT-FND Release 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the open listening ports to minimize the risk of exploitation.

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02416
CVE-2017-6780

Produtos afetados

Cisco Connected Grid Network Management System
Iot Field Network Director