漏洞标题
Cisco IOS XE软件DNS NAT协议应用层网关拒绝服务漏洞
漏洞描述信息
Cisco IOS XE软件DNS NAT协议应用层网关拒绝服务漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
漏洞描述信息
A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a logic error that occurs when an affected device inspects certain DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through an affected device that is performing NAT for DNS packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition on an affected device. The vulnerability can be exploited only by traffic that is sent through an affected device via IPv4 packets. The vulnerability cannot be exploited via IPv6 traffic.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
对因果或异常条件的不恰当检查
漏洞标题
Cisco IOS XE Software 代码问题漏洞
漏洞描述信息
Cisco IOS XE Software是美国思科(Cisco)公司的一个操作系统。用于企业有线和无线访问,汇聚,核心和WAN的单一操作系统,Cisco IOS XE降低了业务和网络的复杂性。 Cisco IOS XE Software 存在安全漏洞,该漏洞源于受影响的设备在检查某些DNS数据包时发生逻辑错误。攻击者可利用该漏洞可能会导致受影响的设备重新加载。
CVSS信息
N/A
漏洞类别
代码问题