Thursday, November 16, 2017

Cisco RF Gateway 1 TCP Connection Denial of Service Vulnerability

A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of service (DoS) condition.

The vulnerability is due to a processing error with TCP connections to the affected device. An attacker could exploit this vulnerability by establishing a large number of TCP connections to an affected device and not actively closing those TCP connections. A successful exploit could allow the attacker to prevent the affected device from delivering SDV or VoD streams to set-top boxes.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2ijt3yD
Security Impact Rating: Medium
CVE: CVE-2017-12318

from Cisco Security Advisory http://ift.tt/2ijt3yD

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.