Boletines de Vulnerabilidades

Cisco Firepower 9000 USB Kernel Denial of Service Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the USB driver of Cisco Firepower 9000 could allow an unauthenticated, local attacker with physical access to the device to send invalid USB commands to the kernel and cause a denial of service (DoS) condition. The vulnerability is due to insufficient sanitization of USB input parameters. An attacker could exploit this vulnerability by using crafted USB user inputs to send invalid USB commands to the kernel.Cisco has not released software updates that address this

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-fire?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Firepower%209000%20USB%20Kernel%20Denial%20of%20Service%20Vulnerabili

Identificadores estándar

Propiedad Valor
CVE CVE-2015-6369.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-18

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT