Lucene search

K
ciscoCiscoCISCO-SA-20120809-CVE-2012-1346
HistoryAug 09, 2012 - 9:12 p.m.

Cisco Emergency Responder Remote Denial of Service Vulnerability

2012-08-0921:12:50
tools.cisco.com
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.002

Percentile

53.2%

Cisco Emergency Responder contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system.

The vulnerability is due to the improper handling of malformed UDP packets by the affected software. An unauthenticated, remote attacker could exploit this vulnerability by submitting malformed UDP packets to the vulnerable software. If successful, the attacker could cause a targeted device to consume excessive CPU resources, resulting in a DoS condition.

Cisco has confirmed this vulnerability and released software updates.

A successful exploit could allow an attacker to cause a device to stop responding, potentially preventing authorized users from accessing network resources served by the targeted device.

To exploit the vulnerability, an attacker must send malformed UDP packets to a targeted device. The attacker may need access to trusted, internal networks, which could limit the likelihood of a successful exploit.

This alert contains CVSS scoring supplied by Cisco, the primary vendor of the affected product. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoemergency_responderMatchany
OR
ciscoemergency_responderMatchany
VendorProductVersionCPE
ciscoemergency_responderanycpe:2.3:a:cisco:emergency_responder:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.002

Percentile

53.2%

Related for CISCO-SA-20120809-CVE-2012-1346