Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm34-xr6q-46qf

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

EPSS

Процентиль: 84%
0.02311
Низкий

8.6 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

CVSS3: 8.6
fstec
больше 2 лет назад

Уязвимость служб HTTP-сервера и IP-телефонии (Telephony Service операционной системы Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02311
Низкий

8.6 High

CVSS3

Дефекты

CWE-476