PT-2016-4725 · Cisco · Cisco Videoscape Distribution Suite For Internet Streaming
Published
2016-03-01
·
Updated
2016-12-03
·
CVE-2016-1353
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) versions 3.3(0) through 4.1(0)
Description
The issue is related to the TCP implementation, which does not properly handle new TCP sessions when a previous session is in a FIN wait state. This allows remote attackers to cause a denial of service, resulting in a TCP outage, by sending FIN packets.
Recommendations
For versions 3.3(0) through 4.1(0), consider temporarily restricting the handling of FIN packets to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Videoscape Distribution Suite For Internet Streaming