PT-2017-17207 · Cisco · Cisco Remote Expert Manager

Published

2017-05-22

·

Updated

2019-10-09

·

CVE-2017-6641

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Remote Expert Manager Software version 11.0.0
Description A vulnerability in the TCP connection handling functionality could allow an unauthenticated, remote attacker to disable TCP ports and cause a denial of service (DoS) condition on an affected system. The issue is due to a lack of rate-limiting functionality in the TCP Listen application. An attacker could exploit this by sending a crafted TCP traffic stream, such as a stream with the TCP FIN bit set in all packets, to flood an affected device. A successful exploit could cause certain TCP listening ports to stop accepting incoming connections for a period or until the device is restarted, resulting in a DoS condition. System resources like CPU and memory could also be exhausted during the attack.
Recommendations For Cisco Remote Expert Manager Software version 11.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6641

Affected Products

Cisco Remote Expert Manager