PT-2017-3051 · Schneider Electric · Cisco Connected Grid Network Management System+1
Publicado
2017-09-06
·
Atualizado
2019-10-09
·
CVE-2017-6780
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Connected Grid Network Management System versions prior to IoT-FND Release 4.0
IoT Field Network Director versions prior to IoT-FND Release 4.0
Description
A vulnerability in the TCP throttling process could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart. This is due to insufficient rate-limiting protection. An attacker could exploit this by sending a high rate of TCP packets to a specific group of open listening ports on a targeted device, allowing them to cause the system to consume additional memory. If enough available memory is consumed, the system will restart, creating a temporary denial of service (DoS) condition. The DoS condition will end after the device has finished the restart process.
Recommendations
For Connected Grid Network Management System versions prior to IoT-FND Release 4.0, update to IoT-FND Release 4.0 or later to resolve the issue.
For IoT Field Network Director versions prior to IoT-FND Release 4.0, update to IoT-FND Release 4.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the open listening ports to minimize the risk of exploitation.
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Connected Grid Network Management System
Iot Field Network Director