CVE-2010-0137: High severity Cisco IOS XR vulnerability
Published Jan 21, 2010
·Updated
Unspecified vulnerability in the sshdchildhandler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.
Affected Software
9 affected components
Cisco IOS XR=3.4.1
Cisco IOS XR=3.4.2
Cisco IOS XR=3.4.3
Cisco IOS XR=3.5.2
Cisco IOS XR=3.5.3
Cisco IOS XR=3.5.4
Cisco IOS XR=3.6.0
Cisco IOS XR=3.6.1
Cisco IOS XR=3.7.0
Remediation
Event History
Jan 21, 2010
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:30 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0137?
CVE-2010-0137 has a severity level that allows remote attackers to cause a denial of service.
2
How do I fix CVE-2010-0137?
To fix CVE-2010-0137, it is recommended to upgrade to a non-vulnerable version of Cisco IOS XR.
3
Which versions of Cisco IOS XR are affected by CVE-2010-0137?
CVE-2010-0137 affects Cisco IOS XR versions from 3.4.1 to 3.7.0.
4
What type of attack is possible through CVE-2010-0137?
CVE-2010-0137 allows for denial of service attacks resulting in process crashes and memory consumption.
5
What component of Cisco IOS XR is impacted by CVE-2010-0137?
CVE-2010-0137 impacts the sshd_child_handler process in the SSH server of Cisco IOS XR.