Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpqj-275w-f6mr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

EPSS

Процентиль: 66%
0.00506
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 12 лет назад

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

EPSS

Процентиль: 66%
0.00506
Низкий

Дефекты

CWE-287