Cisco IOS-XE update time: Squash that DoS bug

  • 30 July 2015
  • 0 replies
  • 119 views

Userlevel 7
Badge +54

Fixes how the daemon triggers error messages for packets it can't reassemble

30 Jul 2015 at 02:58, Richard Chirgwin
 
Bad error message handling has opened up Cisco's IOS-XE versions prior to 3.13S to a remote denial-of-service (DoS) attack.
 
The company's threat advisory hints that the exploit was brought to Cisco's attention by an independent researcher, since it states that "functional exploit code exists; however, the code is not known to be publicly available."
 
IOS XE is a Linux daemon version of the Borg's operating system that abstracts routing functions away from platform-specific interfaces.
 
Full Article

0 replies

Be the first to reply!

Reply