Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8c4-6cm2-mvxv

Опубликовано: 16 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-770
CWE-789

Связанные уязвимости

CVSS3: 5.5
nvd
почти 4 года назад

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость реализации протокола NETCONF микропрограммного обеспечения маршрутизаторов Cisco SD-WAN vEdge, позволяющая нарушителю вызвать отказ в обслуживании или вызвать аварийное завершение работы приложения

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-770
CWE-789