CVE-2010-2836: High severity cisco ios vulnerability
Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is enabled, allows remote attackers to cause a denial of service (memory consumption) by improperly disconnecting SSL sessions, leading to connections that remain in the CLOSE-WAIT state, aka Bug ID CSCtg21685.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2836?
CVE-2010-2836 is classified as a denial of service vulnerability with moderate severity.
How do I fix CVE-2010-2836?
To remediate CVE-2010-2836, update your Cisco IOS version to a non-affected release where the SSL VPN memory leak issue is resolved.
What impact does CVE-2010-2836 have on affected systems?
CVE-2010-2836 can lead to a denial of service by causing excessive memory consumption due to lingering SSL sessions.
Which Cisco IOS versions are affected by CVE-2010-2836?
CVE-2010-2836 affects specific versions of Cisco IOS including 12.4, 15.0, and 15.1.
Can CVE-2010-2836 be exploited remotely?
Yes, CVE-2010-2836 can be exploited remotely by attackers disconnecting SSL sessions improperly.