Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105671
Categoría:CISCO
Título:Cisco IOS Software and IOS XE Software mDNS Gateway Denial of Service Vulnerability
Resumen:A vulnerability in the multicast DNS (mDNS) gateway function of; Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to reload the vulnerable device.;; The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this; vulnerability by sending malformed IP version 4 (IPv4) or IP version 6 (IPv6) packets on UDP port 5353.; An exploit could allow the attacker to cause a denial of service (DoS) condition.;; Cisco has released software updates that address this vulnerability. This advisory is available at the references.;; Note: The March 25, 2015, Cisco IOS & XE Software Security Advisory bundled publication includes seven Cisco Security Advisories.; The advisories address vulnerabilities in Cisco IOS Software and Cisco IOS XE Software. Individual publication links are in; Cisco Event Response: Semiannual Cisco IOS & XE Software Security Advisory Bundled Publication at the references.
Descripción:Summary:
A vulnerability in the multicast DNS (mDNS) gateway function of
Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to reload the vulnerable device.

The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this
vulnerability by sending malformed IP version 4 (IPv4) or IP version 6 (IPv6) packets on UDP port 5353.
An exploit could allow the attacker to cause a denial of service (DoS) condition.

Cisco has released software updates that address this vulnerability. This advisory is available at the references.

Note: The March 25, 2015, Cisco IOS & XE Software Security Advisory bundled publication includes seven Cisco Security Advisories.
The advisories address vulnerabilities in Cisco IOS Software and Cisco IOS XE Software. Individual publication links are in
Cisco Event Response: Semiannual Cisco IOS & XE Software Security Advisory Bundled Publication at the references.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-0650
Cisco Security Advisory: 20150325 Cisco IOS Software and IOS XE Software mDNS Gateway Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-mdns
http://www.securitytracker.com/id/1031979
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.