Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
BID:18955
CVE-2006-3596 |Info
Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
| Bugtraq ID: | 18955 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2006 12:00AM |
| Updated: | Jul 13 2006 11:18PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco IPS 4200 Series Sensors Cisco Intrusion Prevention System 5.1(p1) Cisco Intrusion Prevention System 5.1(1e) Cisco Intrusion Prevention System 5.1(1d) Cisco Intrusion Prevention System 5.1(1c) Cisco Intrusion Prevention System 5.1(1b) Cisco Intrusion Prevention System 5.1(1) Cisco Intrusion Prevention System 5.1 (1a) |
| Not Vulnerable: | |
Discussion
Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
Cisco Intrusion Prevention System is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash an affected device, effectively denying service.
This issue is documented in Cisco bug ID CSCsd36590.
This issue affects 42xx IPS appliances running affected versions of the IPS software.
Cisco Intrusion Prevention System is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash an affected device, effectively denying service.
This issue is documented in Cisco bug ID CSCsd36590.
This issue affects 42xx IPS appliances running affected versions of the IPS software.
Exploit / POC
Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
An attacker employs standard networking tools to exploit this issue.
An attacker employs standard networking tools to exploit this issue.
Solution / Fix
Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
Solution:
The vendor has released an update addressing this issue. Please see the referenced vendor advisory for details on obtaining the appropriate updates.
Solution:
The vendor has released an update addressing this issue. Please see the referenced vendor advisory for details on obtaining the appropriate updates.
References
Cisco Intrusion Prevention System Malformed Packet Denial Of Service Vulnerability
References:
References: