Cisco IOS XE の Simple Network Management Protocol サブシステムにおけるリソース管理に関する脆弱性
| Title |
Cisco IOS XE の Simple Network Management Protocol サブシステムにおけるリソース管理に関する脆弱性
|
| Summary |
Cisco IOS XE の Simple Network Management Protocol (SNMP) サブシステムには、リソース管理に関する脆弱性が存在します。 ベンダは、本脆弱性を Bug ID CSCvb94392 として公開しています。
|
| Possible impacts |
サービス運用妨害 (DoS) 攻撃が行われる可能性があります。 |
| Solution |
ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date |
April 19, 2017, midnight |
| Registration Date |
May 25, 2017, 6:07 p.m. |
| Last Update |
May 25, 2017, 6:07 p.m. |
|
CVSS3.0 : 警告
|
| Score |
6.3
|
| Vector |
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H |
|
CVSS2.0 : 警告
|
| Score |
6.3
|
| Vector |
AV:N/AC:M/Au:S/C:N/I:N/A:C |
Affected System
| シスコシステムズ |
|
Cisco IOS
|
|
Cisco IOS XE
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2017年05月25日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2017-6615
| Summary |
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when the affected software processes an SNMP read request that contains certain criteria for a specific object ID (OID) and an active crypto session is disconnected on an affected device. An attacker who can authenticate to an affected device could trigger this vulnerability by issuing an SNMP request for a specific OID on the device. A successful exploit will cause the device to restart due to an attempt to access an invalid memory region. The attacker does not control how or when crypto sessions are disconnected on the device. Cisco Bug IDs: CSCvb94392.
|
| Publication Date |
April 21, 2017, 7:59 a.m. |
| Registration Date |
Jan. 26, 2021, 1:27 p.m. |
| Last Update |
Nov. 21, 2024, 12:30 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:ios_xe:3.16.0s:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:o:cisco:ios_xe:3.16.2s:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:o:cisco:ios_xe:3.16.0cs:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:o:cisco:ios_xe:3.16.1s:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:o:cisco:ios_xe:3.16.1as:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List