Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
AV:N/AC:L/Au:N/C:N/I:N/A:C
Vendors | Products |
---|---|
Cisco |
|
Configuration 1 [-]
|
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-smi | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/93203 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1036914 | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-287-04 | Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2016-10-05T20:00:00
Updated: 2017-07-29T09:57:01
Reserved: 2016-07-26T00:00:00
Link: CVE-2016-6385
JSON object: View
NVD Information
Status : Modified
Published: 2016-10-05T20:59:05.477
Modified: 2017-07-30T01:29:11.227
Link: CVE-2016-6385
JSON object: View
Redhat Information
No data.
CWE