Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
A vulnerability has been reported in Cisco IOS XE, which can be exploited by malicious people to cause a DoS (Denial of Service).
IMPACT: NORMAL
PUBLISH DATE: 27-09-2018
OVERVIEW
There’s an error within the web framework of Cisco IOS XE when processing HTTP packets. This error can be exploited by people with malicious intent to cause a buffer overflow via a specially crafted HTTP packet. This may cause Denial of Service. The vendor has released update for the vulnerability.
ANALYSIS
An unauthenticated remote attacker could cause a buffer overflow condition on an affected device by exploiting a vulnerability within the web framework of Cisco IOS XE software, resulting in a denial of service (DoS) condition.
When an attacker exploits the vulnerability, the affected software improperly parses malformed HTTP packets that are sent to an affected device for processing. Successful exploitation yields a buffer overflow resulting in a DOS condition.
However, successful exploitation requires the HTTP Server feature to be enabled.
AFFECTED PRODUCTS
Cisco IOS XE Denali 16.3.x
Cisco IOS XE 3.2.x
UPDATE
Please follow the vendor’s advisory on how to check the running version of your product, whether it’s affected or not, and the available updates.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-webdos
If you think you are a victim of a cyber-security attack. Immediately send an email to info@rewterz.com for a rapid response.