Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
BID:29216
Info
Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
| Bugtraq ID: | 29216 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1749 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2008 12:00AM |
| Updated: | May 15 2008 02:35PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Cisco CSM-S 2.1(7) Cisco CSM-S 2.1(6) Cisco CSM-S 2.1(5) Cisco CSM-S 2.1(3) Cisco CSM-S 2.1(2) Cisco CSM 4.2(8) Cisco CSM 4.2(7) Cisco CSM 4.2(6) Cisco CSM 4.2(5) Cisco CSM 4.2(4) Cisco CSM 4.2(3a) Cisco CSM 4.2(3) Cisco CMS-S 2.1(4) |
| Not Vulnerable: | |
Discussion
Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
Cisco Content Switching Module (CSM) and Content Switching Module with SSL (CSM-S) are prone to a denial-of-service vulnerability because of a memory leak. This issue occurs when CSM and CSM-S are configured to use layer 7 load balancing.
An attacker can exploit this issue to cause devices using the module to stop accepting TCP connections or to overload, denying service to legitimate users.
Cisco Content Switching Module (CSM) and Content Switching Module with SSL (CSM-S) are prone to a denial-of-service vulnerability because of a memory leak. This issue occurs when CSM and CSM-S are configured to use layer 7 load balancing.
An attacker can exploit this issue to cause devices using the module to stop accepting TCP connections or to overload, denying service to legitimate users.
Exploit / POC
Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Cisco Content Switching Module Memory Leak (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco Content Switching Module Memory Leak (Cisco)