Wednesday, October 3, 2018

Cisco Remote PHY IPv4 Fragment Denial of Service Vulnerability

A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.

The vulnerability is due to the affected software improperly validating and calculating certain numerical values in IPv4 packets that are sent to an affected device. An attacker could exploit this vulnerability by sending malicious IPv4 traffic to an affected device. A successful exploit could allow the attacker to disrupt the flow of IPv4 traffic on the affected device, which could cause the device to reload and result in a DoS condition.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-phy-ipv4-dos


Security Impact Rating: Medium
CVE: CVE-2018-15391

from Cisco Security Advisory https://ift.tt/2P74vHn

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.