3 results (0.002 seconds)

CVSS: 5.9EPSS: 1%CPEs: 3EXPL: 0

23 Jun 2015 — Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and an MPLS IPv6 VPN are configured, allows remote attackers to cause a denial of service (PXF process crash) by sending malformed MPLS 6VPE packets quickly, aka Bug ID CSCud83396. Condición de carrera en Cisco IOS 12.2SCH en el módulo Performance Routing Engine (PRE) en los dispositivos uBR10000, cuando NetFlow y una VPN MPLS IPv6 están configurados, permite a atacantes remotos causar una de... • http://tools.cisco.com/security/center/viewAlert.x?alertId=39439 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 0

23 Jun 2015 — Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug ID CSCue65051. Fuga de memoria en Cisco IOS 12.2 en el módulo Performance Routing Engine (PRE) en los dispositivos uBR10000 permite a usuarios remotos autenticados causar una denegación de servicio (consumo de memoria o caída del proceso PXF) mediante e... • http://tools.cisco.com/security/center/viewAlert.x?alertId=39440 • CWE-399: Resource Management Errors •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

20 Jun 2015 — Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203. Cisco IOS 12.2SCH en Cable Modem Termination Systems (CMTS) de los routers uBR10000 no restringe correctamente el acceso al servicio IP Detail Record (IPDR), lo que permite a atacantes remotos obtener in... • http://tools.cisco.com/security/center/viewAlert.x?alertId=39432 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •