Cisco Prime Network Denial of Service Vulnerability (CVE-2018-0137)
Cisco Prime Network Denial of Service Vulnerability (CVE-2018-0137)
Release date:
Updated on:
Affected Systems:
Cisco Prime Network
Description:
Bugtraq id: 102955
CVE (CAN) ID: CVE-2018-0137
Cisco Prime Network is an integrated component of Cisco Prime for ip ngn suite and also a single-host product.
Cisco Prime Network has a security vulnerability in the TCP throttling process, which can be exploited by unauthenticated remote attackers to cause affected devices to reject services. This vulnerability is caused by the failure of TCP listening port rate limit protection.
<* Source: vendor
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-cpn
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20180207-cpn) and patches for this:
Cisco-sa-20180207-cpn: Cisco Prime Network TCP Denial of Service Vulnerability
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-cpn