BDU:2017-00655

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

10.0critical2.0
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Уязвимость в коде обработки протокола CMP сетевых устройств Cisco Systems Inc. связана с некорректной обработкой Telnet-опций, специфичных для протокола CMP, а также отсутствием ограничений на прием и обработку Telnet-сообщений из источников, не являющихся членами кластера. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код с повышенными привилегиями или вызвать отказ в обслуживании (перезагрузку устройства) путем отправки ему специально сформированных CMP-опций в рамках Telnet-соединения

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: BDU:2017-00655

Source: bdu_exploit

URL: https://bdu.fstec.ru/vul

Exploit ID: 41872

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41872

Exploit ID: 42122

Source: exploitdb

URL: https://www.exploit-db.com/exploits/42122

Recommendations

Source: bdu

Использование рекомендаций:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp

URL: https://bdu.fstec.ru/vul/2017-00655

Vulnerable Software (318)

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2350-48td-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2350-48td-sd switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2360-48td-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2918-24tc-c switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2918-24tt-c switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2918-48tc-c switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2918-48tt-c switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2928-24tc-c switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24lc-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24lt-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24pc-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24pc-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24tc-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24tc-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-24tt-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-48pst-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-48pst-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-48tc-l switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: cisco systems inc.

Product: catalyst 2960-48tc-s switch

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu