Executive Summary
Summary | |
---|---|
Title | Cisco Intrusion Prevention System Management Interface Denial of Service and Fragmented Packet Evasion Vulnerabilities |
Informations | |||
---|---|---|---|
Name | cisco-sa-20060920-ips | First vendor Publication | 2006-09-20 |
Vendor | Cisco | Last vendor Modification | 2006-09-20 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Cisco Intrusion Prevention System (IPS) software contains a denial of service vulnerability in web administration interface involving malformed Secure Socket Layer (SSL) packets and a fragmented packet evasion vulnerability. |
Original Source
Url : http://www.cisco.com/warp/public/707/cisco-sa-20060920-ips.shtml |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
29037 | Cisco IPS/IDS Web Administration Malformed SSLv2 Client Hello DoS Cisco IPS and IDS contain a flaw that may allow a remote denial of service. The issue is triggered when a malformed SSLv2 Client Hello packet is sent to the management interface, and will result in loss of availability for the management interface. |
29036 | Cisco IPS Fragmented IP Packet Sequence Detection Bypass Cisco IPS contains a flaw that may allow a malicious user to bypass its protection. The issue is triggered when a specially crafted sequence of fragmented IP packets is passed through the device, which allows malicious traffic to evade inspection. It is possible that the flaw may allow unauthorized network access resulting in a loss of integrity. |