Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hxc-5mh2-9rxg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

EPSS

Процентиль: 70%
0.00641
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.6
nvd
больше 5 лет назад

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

CVSS3: 8.6
fstec
больше 5 лет назад

Уязвимость службы обработки трафика IPv6 микропрограммного обеспечения маршрутизаторов Cisco Small Business 250 Series, Cisco Small Business 350 Series, Cisco Small Business 350X Series, Cisco Small Business 550X Series, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00641
Низкий

Дефекты

CWE-20