Lucene search

K
ciscoCiscoCISCO-SA-20171115-RF-GATEWAY-1
HistoryNov 15, 2017 - 4:00 p.m.

Cisco RF Gateway 1 TCP Connection Denial of Service Vulnerability

2017-11-1516:00:00
tools.cisco.com
21

EPSS

0.001

Percentile

48.1%

A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of service (DoS) condition.

The vulnerability is due to a processing error with TCP connections to the affected device. An attacker could exploit this vulnerability by establishing a large number of TCP connections to an affected device and not actively closing those TCP connections. A successful exploit could allow the attacker to prevent the affected device from delivering SDV or VoD streams to set-top boxes.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-rf-gateway-1 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-rf-gateway-1”]

Affected configurations

Vulners
Node
ciscorf_gateway_1_firmwareMatchany
OR
ciscorf_gateway_1_firmwareMatch1
VendorProductVersionCPE
ciscorf_gateway_1_firmwareanycpe:2.3:o:cisco:rf_gateway_1_firmware:any:*:*:*:*:*:*:*
ciscorf_gateway_1_firmware1cpe:2.3:o:cisco:rf_gateway_1_firmware:1:*:*:*:*:*:*:*

EPSS

0.001

Percentile

48.1%

Related for CISCO-SA-20171115-RF-GATEWAY-1