OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA11045] Cisco Content Services Switch 11000 Series Denial of Service

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Mar 05 2004 - 03:20:57 CST


TITLE:
Cisco Content Services Switch 11000 Series Denial of Service

SECUNIA ADVISORY ID:
SA11045

VERIFY ADVISORY:
http://secunia.com/advisories/11045/

CRITICAL:
Not critical

IMPACT:
DoS

WHERE:
From local network

OPERATING SYSTEM:
Cisco Content Services Switch 11000 Series

DESCRIPTION:
Cisco has reported a vulnerability in Cisco Content Services Switch
11000 Series, allowing malicious people to cause a Denial of
Service.

The device reportedly fails to handle certain malformed packets to
port 5002/UDP (app-udp) on the management port, which can be
exploited to cause a vulnerable device to reload.

Successful exploitation requires access to the management network.

The vulnerability affects devices running Cisco WebNS release 5.0(x)
and 6.10(x).

SOLUTION:
Management networks should only be accessible by trusted users.

The following versions are not vulnerable:
* WebNS 5.0(04.07)S and later.
* WebNS 6.10(02.05)S and later.

http://www.cisco.com/pcgi-bin/tablebuild.pl/webns-interim?psrtdcat20e2

PROVIDED AND/OR DISCOVERED BY:
Reported by vendor.

ORIGINAL ADVISORY:
http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------