← volver
CVE-2019-12647

Cisco IOS and IOS XE Software IP Ident Denial of Service Vulnerability

CVSS 8.6 HIGHEPSS 2.0%CWE-476
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.6EPSS 2.0%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
25 sep 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by opening a TCP connection to specific ports and sending traffic over that connection. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Productos afectados
Cisco · Cisco IOS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →