Guest

Preview Tool

Cisco Bug: CSCuq39550 - Cisco IPS MainApp Denial of Service Vulnerability

Last Modified

Nov 01, 2017

Products (1)

  • Cisco IPS 4200 Series Sensors

Known Affected Releases

7.1(8)S17 7.3(2)E4

Description (partial)

Symptom:
A vulnerability in the web framework of the Cisco Intrusion Prevention System (IPS) Software could allow an authenticated, remote attacker to cause MainApp to hang intermittently due to the authentication manager process creating a denial of service (DoS) condition.

The vulnerability is due to improper handling of user tokens. An attacker could exploit this vulnerability by sending a crafted connection request to the Cisco IPS management interface.

Conditions:
Default configuration.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.