Executive Summary

Summary
Title Cisco IOS Software Network Address Translation Vulnerabilities
Informations
Name cisco-sa-20110928-nat First vendor Publication 2010-12-16
Vendor Cisco Last vendor Modification 2011-09-28
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of the following protocols:

* NetMeeting Directory (Lightweight Directory Access Protocol, LDAP)
* Session Initiation Protocol (Multiple vulnerabilities)
* H.323 protocol

All the vulnerabilities described in this document are caused by packets in transit on the affected devices when those packets require application layer translation.

Cisco has released free software updates that address these vulnerabilities.

Original Source

Url : http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9 (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-399 Resource Management Errors

OVAL Definitions

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Hardware 286
Os 5812
Os 2

Open Source Vulnerability Database (OSVDB)

Id Description
75925 Cisco IOS Network Address Translation UDP SIP Packet Parsing Memory Exhaustio...

75924 Cisco IOS Network Address Translation MPLS UDP SIP Packet Parsing Remote DoS

75923 Cisco IOS Network Address Translation UDP SIP Packet Parsing Remote DoS

75922 Cisco IOS Network Address Translation TCP SIP Packet Parsing Remote DoS

75921 Cisco IOS Network Address Translation H.323 Packet Parsing Remote DoS

75920 Cisco IOS Network Address Translation LDAP Packet Parsing Remote DoS

Nessus® Vulnerability Scanner

Date Description
2011-09-29 Name : The remote device is missing a vendor-supplied security patch.
File : cisco-sa-20110928-nathttp.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 10:22:01
  • Multiple Updates