Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105644
Categoría:CISCO
Título:Cisco NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability (cisco-sa-20160323-lisp)
Resumen:A vulnerability in the Locator/ID Separation Protocol (LISP) of; Cisco NX-OS Software running on the Cisco Nexus 7000 and Nexus 7700 Series Switches with an M1; Series Gigabit Ethernet Module could allow an unauthenticated, remote attacker to cause a reload; of the vulnerable device.
Descripción:Summary:
A vulnerability in the Locator/ID Separation Protocol (LISP) of
Cisco NX-OS Software running on the Cisco Nexus 7000 and Nexus 7700 Series Switches with an M1
Series Gigabit Ethernet Module could allow an unauthenticated, remote attacker to cause a reload
of the vulnerable device.

Vulnerability Insight:
The vulnerability is due to a lack of proper input validation
when a malformed LISP packet header is received. An attacker could exploit this vulnerability by
sending a malformed LISP packet on UDP port 4341.

Vulnerability Impact:
An exploit could allow the attacker to cause a denial of service
(DoS) condition.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-1351
Cisco Security Advisory: 20160323 Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160323-lisp
http://www.securitytracker.com/id/1035383
http://www.securitytracker.com/id/1035384
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.