The vulnerability is due to improper handling of crafted IKEv2 packets. The vulnerability applies only to IKEv2 devices acting as clients or IKEv2 initiators. An attacker could exploit this vulnerability by sending crafted packets to the affected devices. An attacker, however, would need to be able to force the affected device to connect to a rogue IKEv2 server under its control. An exploit could allow the attacker to cause a reload of the affected system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: http://ift.tt/2dRSnfi
The vulnerability is due to improper handling of crafted IKEv2 packets. The vulnerability applies only to IKEv2 devices acting as clients or IKEv2 initiators. An attacker could exploit this vulnerability by sending crafted packets to the affected devices. An attacker, however, would need to be able to force the affected device to connect to a rogue IKEv2 server under its control. An exploit could allow the attacker to cause a reload of the affected system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: http://ift.tt/2dRSnfi
Security Impact Rating: Medium
CVE: CVE-2016-6423
from Cisco Security Advisory http://ift.tt/2dRSnfi
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.