Boletines de Vulnerabilidades

Cisco ASR 5000 and ASR 5500 TACACS Denial of Service Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the TACACS protocol implementation of the Cisco Aggregation Services Router (ASR) 5000 and ASR 5500 (ASR5K) System Software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition because the vpnmgr process restarts. The vulnerability is due to improper input validation of the TACACS packet header. An attacker could exploit this vulnerability by sending a crafted TACACS packet to the device. An exploit could allow the attacker to

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151012-asr?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20ASR%205000%20and%20ASR%205500%20TACACS%20Denial%20of%20Service%20Vulne

Identificadores estándar

Propiedad Valor
CVE CVE-2015-6334.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-10-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT