A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by opening a TCP connection to specific ports and sending traffic over that connection. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1100
Subscribe
4221
Subscribe
4321
Subscribe
4351
Subscribe
4431
Subscribe
4451-x
Subscribe
Asr 1000
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-x
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-x
Subscribe
Asr 900
Subscribe
Asr 920-10sz-pd
Subscribe
Asr 920-12cz-a
Subscribe
Asr 920-12cz-d
Subscribe
Asr 920-12sz-im
Subscribe
Asr 920-24sz-im
Subscribe
Asr 920-24sz-m
Subscribe
Asr 920-24tz-m
Subscribe
Asr 920-4sz-a
Subscribe
Asr 920-4sz-d
Subscribe
Cloud Services Router 1000v
Subscribe
Ios Xe
Subscribe
Ncs 4201
Subscribe
Ncs 4202
Subscribe
Ncs 4206
Subscribe
Ncs 4216
Subscribe
Network Convergence System 520
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4238 | A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by opening a TCP connection to specific ports and sending traffic over that connection. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 19 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-19T18:56:32.819Z
Reserved: 2019-06-04T00:00:00
Link: CVE-2019-12647
Updated: 2024-08-04T23:24:39.039Z
Status : Modified
Published: 2019-09-25T20:15:10.417
Modified: 2024-11-21T04:23:15.310
Link: CVE-2019-12647
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD