First published: Tue Sep 04 2007(Updated: )
Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Content Services Switch 11000 | ||
Cisco WebNS | =8.20.0.1 | |
OpenSSH | =3.0.2p1 | |
TeamF1 SSHield | =1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4654 has a high severity rating due to its potential to cause a denial of service and device crashes.
To fix CVE-2007-4654, you should update your Cisco WebNS to a secure version that patches this vulnerability.
Devices affected by CVE-2007-4654 include Cisco Content Services Switch 11000 series with specific versions of Cisco WebNS and OpenSSH.
Yes, CVE-2007-4654 can be exploited by remote attackers sending large packets to the vulnerable devices.
The impact of CVE-2007-4654 on affected systems includes connection slot exhaustion and potential system crashes.