The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition.
Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2eGyp4T
The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition.
Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2eGyp4T
Security Impact Rating: Medium
CVE: CVE-2017-6631
from Cisco Security Advisory http://ift.tt/2eGyp4T
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.