Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j86j-prqg-7fpq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected device. An attacker could exploit this vulnerability by using UDP port 5060 to send crafted SIP packets through an affected device that is performing NAT for SIP packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected device. An attacker could exploit this vulnerability by using UDP port 5060 to send crafted SIP packets through an affected device that is performing NAT for SIP packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

EPSS

Процентиль: 77%
0.01033
Низкий

7.5 High

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected device. An attacker could exploit this vulnerability by using UDP port 5060 to send crafted SIP packets through an affected device that is performing NAT for SIP packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 8.6
fstec
больше 6 лет назад

Уязвимость реализации протокола SIP (Session Initiation Protocol) и функции NAT (Network Address Translation) шлюза прикладного уровня Application Layer Gateway (ALG) операционной системы Cisco IOS XE, позволяющая нарушителю вызвать перезагрузку уязвимого устройства

EPSS

Процентиль: 77%
0.01033
Низкий

7.5 High

CVSS3

Дефекты

CWE-665