Executive Summary

Summary
Title Multiple Cisco Products Disk Utilization Denial of Service Vulnerability
Informations
Name cisco-sa-20180606-diskdos First vendor Publication 2018-06-06
Vendor Cisco Last vendor Modification 2018-06-06
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.

The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file is allowed to consume the majority of available disk space on the appliance. An attacker could exploit this vulnerability by sending crafted remote connection requests to the appliance. Successful exploitation could allow the attacker to increase the size of a system log file so that it consumes most of the disk space. The lack of available disk space could lead to a DoS condition in which the application functions could operate abnormally, making the appliance unstable.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-diskdos ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-diskdos"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJbGAY6XBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczDRsQAMBtXM4Q4eWqghESnV7dkba+xrYT LJEqrnsV6NCupJ/PIWXjuoYjgsX2m7NHzo6N3vZFcZgQ28cZNAaTtTJ/spbsLfU5 SlgAPHIPeSbOEXZm3PQV4Ft5roXWimMfX+LLljcJVbqFMVK1dbl8XG51ss78lX2u P2lzjVne2Adx9zedLIeGNm/i5mg8LUUjjxFiwY+LN+Idpq7H+Vl6k+l5IpXU/XJy ohueZ9I3HpljERzMlKhRjaUPxMLLI8iAfJ1KRDrbjSpxKTQBv36E+4zlXl/NNzhO eQLkD495vlq5dXsR5TCWRoaMYWwG5UD+aPvlGcs5+5L+cG1TdfPBtwFeLnC/lRB +am6fRNbDAWkPnms5Zi0/7g+V9O/UzB0/f13854pOb3ANUJFUNN08HpmFCSuel5+p 44RuaHmmnUtFdLwMOKms3Q7udFsNjPVoD6/6YrKNK6Mf8nOkKSy6Bt1r5iWZLq13 ar49d6pbuMM7/EdHYzH8k2e6Bd5F6JrqqRsOu69/z2KUIB6EHf6vtn5+LyTy/GY/ U3/LnIQCLTl6jVaVmW35gStVpD31CSu1gWl0AEmU5LDApp7gGVM+HGt8eo8dB9n6 jOL1U0IMkdC/SMZ/5PXB1GxMvY1BjLxgC9Y2VEGbYeEldf+MnAc5n5F70Z2HNETt wMJm2NJOV02AahTn =Ahps END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 17
Application 36
Application 10
Application 6
Application 13
Application 1
Application 4
Application 6
Application 244
Application 15
Application 4
Application 117
Application 1
Os 6

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2018-07-23 21:21:39
  • Multiple Updates
2018-06-07 17:21:02
  • Multiple Updates
2018-06-06 21:19:00
  • First insertion