Advisories Blog | G5 Cyber Security

Cisco Security Advisory 20090908-tcp24

Cisco Security Advisory – Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of a TCP connection, an attacker could force the TCP connection to remain in a long-lived state, possibly indefinitely. If enough TCP connections are forced into a long-lived or indefinite state, resources on a system under attack may be consumed, preventing new TCP connections from being accepted. In some cases, a system reboot may be necessary to recover normal system operation. To exploit these vulnerabilities, an attacker must be able to complete a TCP three-way handshake with a vulnerable system. In addition to these vulnerabilities, Cisco Nexus 5000 devices contain a TCP DoS vulnerability that may result in a system crash. This additional vulnerability was found as a result of testing the TCP state manipulation vulnerabilities.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81109/cisco-sa-20090908-tcp24.txt

Source: https://packetstormsecurity.com/files/81109/Cisco-Security-Advisory-20090908-tcp24.html

Exit mobile version