SISCO OSI Stack Remote Denial of Service Vulnerability
BID:20130
Info
SISCO OSI Stack Remote Denial of Service Vulnerability
| Bugtraq ID: | 20130 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2006 12:00AM |
| Updated: | Sep 21 2006 07:46PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
SISCO MMS-EASE 7.10 SISCO ISO Stack 3 SISCO ICCP Toolkit for MMS-EASE 4.10 SISCO AX-S4 MMS 5.01 SISCO AX-S4 ICCP 3.0103 |
| Not Vulnerable: |
SISCO MMS-EASE 8.03 SISCO ICCP Toolkit for MMS-EASE 5.03 SISCO AX-S4 MMS 5.02 SISCO AX-S4 ICCP 3.0155 |
Discussion
SISCO OSI Stack Remote Denial of Service Vulnerability
The SISCO OSI stack for Windows is prone to a remote denial-of-service vulnerability because the software fails to properly handle malformed network packets.
This issue allows remote, unauthenticated attackers to crash affected applications, denying further service to legitimate users.
The SISCO OSI stack for Windows product is used in these products:
- MMS_EASE
- ICCP Toolkit for MMS_EASE
- AX-S4 MMS
- AX-S4 ICCP
SISCO OSI stack 3.x and earlier versions are vulnerable to this issue.
The SISCO OSI stack for Windows is prone to a remote denial-of-service vulnerability because the software fails to properly handle malformed network packets.
This issue allows remote, unauthenticated attackers to crash affected applications, denying further service to legitimate users.
The SISCO OSI stack for Windows product is used in these products:
- MMS_EASE
- ICCP Toolkit for MMS_EASE
- AX-S4 MMS
- AX-S4 ICCP
SISCO OSI stack 3.x and earlier versions are vulnerable to this issue.
Exploit / POC
SISCO OSI Stack Remote Denial of Service Vulnerability
This issue was originally triggered by using the NESSUS vulnerability-scanning application.
This issue was originally triggered by using the NESSUS vulnerability-scanning application.
Solution / Fix
SISCO OSI Stack Remote Denial of Service Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for details.
Solution:
The vendor has released fixes to address this issue. Please see the references for details.
References
SISCO OSI Stack Remote Denial of Service Vulnerability
References:
References:
- Product Page (SISCO)
- RESULTS OF NESSUS VULNERABILITY TESTING (SISCO)
- Vulnerability Note VU#468798 (US-CERT)