IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
BID:37952
Info
IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
| Bugtraq ID: | 37952 |
| Class: | Design Error |
| CVE: |
CVE-2010-1612 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | ErikA |
| Vulnerable: |
IBM Datapower XS40 3.7.2.1 |
| Not Vulnerable: |
IBM Datapower XS40 3.8.0.0 |
Discussion
IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
IBM Datapower XS40 is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to hang, denying service to legitimate users.
IBM Datapower XS40 firmware 3.7.2.1 is vulnerable; other versions may also be affected.
IBM Datapower XS40 is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to hang, denying service to legitimate users.
IBM Datapower XS40 firmware 3.7.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
To exploit this issue, an attacker can use readily available network utilities.
To exploit this issue, an attacker can use readily available network utilities.
Solution / Fix
IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
IBM Datapower XS40 Malformed ICMP Packet Denial of Service Vulnerability
References:
References: