cisco-sa-asr-mem-leak-dos-MTWGHKk3: Cisco StarOS IPv4 Denial of Service Vulnerability
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An attacker could exploit this vulnerability by sending a series of crafted IPv4 packets through an affected device. A successful exploit could allow the attacker to exhaust the available memory and cause an unexpected restart of the npusim process, leading to a DoS condition on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr-mem-leak-dos-MTWGHKk3
Affected Software
Event History
Frequently Asked Questions
What is the severity of Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3?
The severity of Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3 is high due to the potential for denial of service attacks.
How do I fix Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3?
To fix Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3, ensure your Cisco StarOS is updated to the latest patched version provided by Cisco.
What type of attack can exploit Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3?
Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3 can be exploited through a denial of service attack that targets the memory management of the IPv4 protocol handling.
Who is affected by Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3?
Cisco StarOS users are affected by Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3, specifically those utilizing the versions susceptible to the memory leak.
Is authentication required to exploit Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3?
No authentication is required to exploit Cisco-SA-ASR-MEM-LEAK-DOS-MTWGHKk3, making it particularly dangerous for vulnerable networks.