Executive Summary

Summary
Title Cisco IOS Software TFTP Server Denial of Service Vulnerability
Informations
Name cisco-sa-20150722-tftp First vendor Publication 2015-07-22
Vendor Cisco Last vendor Modification 2015-07-22
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.1 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in the TFTP server feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The TFTP server feature is not enabled by default.

Cisco has released software updates that address this vulnerability.

Workarounds that mitigate this vulnerability are available.

This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-tftp BEGIN PGP SIGNATURE Comment: GPGTools - http://gpgtools.org

iQIcBAEBCgAGBQJVrtscAAoJEIpI1I6i1Mx3HRoQAJgb/gd5hd4/WLf/wscI75Me kiOmR7sHm3W7JVO1mmH/g7pmKwzmycXN3BgnhzEl4QRxGR4qzeUMNPfla7dxWM1v umEWXKuY7bfQ9rLgEXaHYTGS62p667PTPpqUid32QYYClKCUfGoL7HwpuwkbbsVi KbheM/L3hLqSID370T7ZfcJccH9urn+OV34cjc2AgKhurmfrx2fCJgW8alwuIdci 4D0Q+qwL8nJ/3f/avqSR+VqW+Oxnx7msINBcNtSjaSthH6rdyJ+IYRfdS3xvrTDe xgdYO9eeaVGNqEDgGNjwMXvOcvLtyLF52ApAC/6G/Dq3BAtGDTm+dLwv/hsHNDoE TbEs80WshkeF4xGQz4qkSQbhYb0YpgU1I+ZCSyzraB1vGsNzUa+atsbeooA8V6Dg V4npx4cBOlr8Ma1KaXIWu8Zuhq3bwZmaH7lE4/f8xVXhG7/ijgHj/QexCpDJV1db i45pxxvxH31+v8rqczsU8HwzQLw20W3obrg2yrt85tNbK4gl/neNGJTi2naiWZ2e U6NjHoo8TZF9EW9/x0iZA1wwaiICr8BNLV/b4LUK6ylM44Kp6AL4W6NCnjPpS7jG ItsVEHi8ZnjTaCwiOEzf/zgniYuGcb25dFsrkRnQG0Ec/FqVDlCB1ChKCi+GhRuu wpT5wP/CY0I6Eo31fmds =v86R END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-399 Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 9
Os 53

Information Assurance Vulnerability Management (IAVM)

Date Description
2015-07-30 IAVM : 2015-A-0175 - Multiple Vulnerabilities in Cisco IOS XE
Severity : Category I - VMSKEY : V0061141
2015-07-30 IAVM : 2015-A-0177 - Cisco IOS Denial of Service Vulnerability
Severity : Category I - VMSKEY : V0061143

Snort® IPS/IDS

Date Description
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35343 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35342 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35341 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35340 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35339 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35338 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35337 - Revision : 1 - Type : PROTOCOL-TFTP
2015-07-22 Cisco IOS TFTP server denial of service attempt
RuleID : 35336 - Revision : 1 - Type : PROTOCOL-TFTP

Nessus® Vulnerability Scanner

Date Description
2015-07-30 Name : The remote device is missing a vendor-supplied security patch.
File : cisco-sa-20150722-tftp-ios.nasl - Type : ACT_GATHER_INFO
2015-07-30 Name : The remote device is missing a vendor-supplied security patch.
File : cisco-sa-20150722-tftp-iosxe.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2015-10-18 17:22:10
  • Multiple Updates
2015-07-31 13:28:34
  • Multiple Updates
2015-07-27 21:31:45
  • Multiple Updates
2015-07-22 21:22:21
  • First insertion