Cisco PIX Firewall Telnet/SSH Subnet Handling Denial Of Service Vulnerability
BID:6110
Info
Cisco PIX Firewall Telnet/SSH Subnet Handling Denial Of Service Vulnerability
| Bugtraq ID: | 6110 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2002 12:00AM |
| Updated: | Nov 05 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Nils Reichen <[email protected]>. |
| Vulnerable: |
Cisco PIX Firewall 6.2.2 |
| Not Vulnerable: |
Cisco PIX Firewall 6.2.2 .111 |
Discussion
Cisco PIX Firewall Telnet/SSH Subnet Handling Denial Of Service Vulnerability
Cisco PIX Firewalls are reported to be prone to a denial of service condition.
The vulnerable condition occurs when telnet/SSH access has been enabled on the firewall for hosts on the internal network. If TCP SYN packets are sent repeatedly to the subnet address, this may cause a denial of service condition.
This issue was reported for Cisco PIX Firewall 6.2.2. Other versions of the PIX operating system may also be affected.
Cisco PIX Firewalls are reported to be prone to a denial of service condition.
The vulnerable condition occurs when telnet/SSH access has been enabled on the firewall for hosts on the internal network. If TCP SYN packets are sent repeatedly to the subnet address, this may cause a denial of service condition.
This issue was reported for Cisco PIX Firewall 6.2.2. Other versions of the PIX operating system may also be affected.
Exploit / POC
Cisco PIX Firewall Telnet/SSH Subnet Handling Denial Of Service Vulnerability
There is no exploit code required. A number of available tools may be used to trigger this condition.
There is no exploit code required. A number of available tools may be used to trigger this condition.
References
Cisco PIX Firewall Telnet/SSH Subnet Handling Denial Of Service Vulnerability
References:
References:
- Cisco PIX SSH/telnet dDOS vulnerability CSCdy51810 (Nils Reichen
) - Re: Cisco PIX SSH/telnet dDOS vulnerability CSCdy51810 (Sharad Ahlawat
)