Executive Summary

Summary
Title Cisco Content Switching Module Memory Leak Vulnerability
Informations
Name cisco-sa-20080514-csm First vendor Publication 2008-04-09
Vendor Cisco Last vendor Modification 2008-05-14
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Cisco Content Switching Module (CSM) and Cisco Content Switching Module with SSL (CSM-S) contain a memory leak vulnerability that can result in a denial of service condition. The vulnerability exists when the CSM or CSM-S is configured for layer 7 load balancing. An attacker can trigger this vulnerability when the CSM or CSM-S processes TCP segments with a specific combination of TCP flags while servers behind the CSM/CSM-S are overloaded and/or fail to accept a TCP connection.

Cisco has released free software updates that address this vulnerability.

Original Source

Url : http://www.cisco.com/en/US/products/products_security_advisory09186a008099 (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-399 Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 7
Application 6

Open Source Vulnerability Database (OSVDB)

Id Description
45201 Cisco Content Switching Module (CSM) TCP Packet Handling Remote Memory Leak DoS

Information Assurance Vulnerability Management (IAVM)

Date Description
2008-05-29 IAVM : 2008-B-0044 - Cisco Content Switching Module Layer 7 Load Balancing Denial of Service Vulne...
Severity : Category I - VMSKEY : V0016024

Nessus® Vulnerability Scanner

Date Description
2013-09-26 Name : The remote switch contains a switching module with a denial of service vulner...
File : cisco-sa-20080514-csm.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 10:21:53
  • Multiple Updates
2013-11-11 12:37:27
  • Multiple Updates