Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.107097
Kategorie:CISCO
Titel:Cisco NX-OS Border Gateway Protocol Denial of Service Vulnerability
Zusammenfassung:A vulnerability in the Border Gateway Protocol (BGP) implementation of;Cisco NX-OS System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS);condition due to the device unexpectedly reloading.
Beschreibung:Summary:
A vulnerability in the Border Gateway Protocol (BGP) implementation of
Cisco NX-OS System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)
condition due to the device unexpectedly reloading.

Vulnerability Insight:
The vulnerability is due to incomplete input validation of the BGP update
messages. An attacker could exploit this vulnerability by sending a crafted BGP update message to the targeted
device. To exploit this vulnerability, an attacker must be able to send the malicious packets over a TCP
connection that appears to come from a trusted BGP peer, or inject malformed messages into the victim's BGP
network.

Vulnerability Impact:
An exploit could allow the attacker to cause the switch to reload
unexpectedly.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.1

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-1454
BugTraq ID: 93417
http://www.securityfocus.com/bid/93417
Cisco Security Advisory: 20161005 Cisco NX-OS Border Gateway Protocol Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-bgp
http://www.securitytracker.com/id/1036950
CopyrightThis script is Copyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.