Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
BID:42371
Info
Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
| Bugtraq ID: | 42371 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-2822 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2010 12:00AM |
| Updated: | Aug 11 2010 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco ACE Module A2(1.3) Cisco ACE Module A2(1.2) Cisco ACE Module A2(1.1) Cisco ACE Module 0 Cisco ACE Application Control Engine Module 3.0(0)A2(2.3) Cisco ACE Application Control Engine Module 3.0(0)A2(2.2.28) Cisco ACE 4710 Appliance A3(2.1) Cisco ACE 4710 Appliance A2(3.0) Cisco ACE 4710 Appliance A1(8a) Cisco ACE 4710 Appliance A1(8.0) Cisco ACE 4710 Appliance 0 |
| Not Vulnerable: |
Cisco ACE Module A2(3.2) Cisco ACE 4710 Appliance A3(2.6) |
Discussion
Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
Cisco ACE Application Control Engine Module and ACE 4710 Application Control Engine are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to crash and reload, denying service to legitimate users.
This issue is tracked by Cisco bug IDs CSCta85227 and CSCtg14858.
Cisco ACE Application Control Engine Module and ACE 4710 Application Control Engine are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to crash and reload, denying service to legitimate users.
This issue is tracked by Cisco bug IDs CSCta85227 and CSCtg14858.
Exploit / POC
Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Cisco ACE Module and Engine RTSP Inspection Denial of Service Vulnerability
References:
References: