First published: Thu Sep 21 2006(Updated: )
The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Intrusion Detection System (IDS) Sensor Software | =4.1\(5b\) | |
Cisco IPS Sensor Software | =5.0\(6\)p1 | |
Cisco IPS Sensor Software | =5.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4910 is categorized with a high severity due to its potential to cause a denial of service.
To mitigate CVE-2006-4910, upgrade to Cisco IDS version 4.1(5c) or IPS version 5.0(6p1) or 5.1(2) and above.
CVE-2006-4910 affects Cisco IDS versions prior to 4.1(5c) and IPS versions prior to 5.0(6p1) and 5.1(2).
CVE-2006-4910 enables remote attackers to perform a denial of service attack by sending a crafted SSLv2 Client Hello packet.
Yes, CVE-2006-4910 can be exploited remotely, leading to an unresponsive device.