Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105647
Categoría:CISCO
Título:Cisco IOS XR Software SCP and SFTP Modules Denial of Service Vulnerability (cisco-sa-20160323-ncs)
Resumen:A vulnerability in the Secure Copy Protocol (SCP) and Secure; FTP (SFTP) modules of Cisco IOS XR Software could allow an authenticated, remote attacker to; overwrite system files and cause a denial of service (DoS) condition.
Descripción:Summary:
A vulnerability in the Secure Copy Protocol (SCP) and Secure
FTP (SFTP) modules of Cisco IOS XR Software could allow an authenticated, remote attacker to
overwrite system files and cause a denial of service (DoS) condition.

Vulnerability Insight:
The vulnerability is due to improper setting of permissions on
the filesystem for certain paths that include system files. An attacker could exploit this
vulnerability by using either the SCP or SFTP client to overwrite system files on the affected
device.

Vulnerability Impact:
An exploit could allow the attacker to overwrite system files
and cause a DoS condition.

Solution:
See the referenced advisory for a solution.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:C/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-1366
Cisco Security Advisory: 20160323 Cisco Network Convergence System 6000 Series Routers SCP and SFTP Modules Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160323-ncs
http://www.securitytracker.com/id/1035407
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.