Release date:
Updated on:
Affected Systems:
Cisco ASR 5000
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65052
CVE (CAN) ID: CVE-2014-0669
The Cisco ASR 5000 series is a carrier-level platform that can be used to deploy high-demand 3G networks and migrate to long-term evolution (LTE.
The Gateway GPRS of the Cisco ASR 5000 Series equipment supports the Wireless Session Protocol (WSP) function of the node (GGSN) component. Security Vulnerabilities exist in implementation. Remote attackers use WSP packets, this vulnerability allows you to bypass the target Top-UP payment restriction and then browse it for free.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0669
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2014-0669) and patches for this:
CVE-2014-0669: Cisco ASR 5000 Series Gateway GPRS Support Node Traffic Bypass Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0669