Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105529
Categoría:CISCO
Título:Cisco IOS XR Software OSPF Link State Advertisement PCE Vulnerability (cisco-sa-20160104-iosxr)
Resumen:A vulnerability in Open Shortest Path First (OSPF) Link State; Advertisement (LSA) handling by Cisco IOS XR Software could allow an unauthenticated, remote; attacker to cause a denial of service (DoS) condition.
Descripción:Summary:
A vulnerability in Open Shortest Path First (OSPF) Link State
Advertisement (LSA) handling by Cisco IOS XR Software could allow an unauthenticated, remote
attacker to cause a denial of service (DoS) condition.

Vulnerability Insight:
The vulnerability is due to the number of OSPF Path Computation
Elements (PCEs) that are configured for an OSPF LSA opaque area update. An attacker could exploit
this vulnerability by sending a crafted OSPF LSA update to an affected device that is running the
vulnerable software and OSPF configuration.

Vulnerability Impact:
A successful exploit could allow the attacker to cause a DoS
condition due to the OSPF process restarting when the crafted OSPF LSA update is received.

Affected Software/OS:
Cisco IOS XR Software Releases 4.1.1, 4.2.0, 4.2.3, 4.3.0,
4.3.2, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-6432
Cisco Security Advisory: 20160104 Cisco IOS XR Software OSPF Link State Advertisement PCE Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160104-iosxr
http://www.securitytracker.com/id/1034570
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.