Cisco IOS Software and Cisco IOS XE Software EnergyWise Crafted Packet Denial of Service Vulnerability
A vulnerability in the EnergyWise module of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of the affected device.
The vulnerability is due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted EnergyWise packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.
Cisco has released free software updates that address this vulnerability.
There are no workarounds for this vulnerability.
This advisory is available at the following link:
http://bit.ly/XEe1qq
from Cisco Security Advisory http://bit.ly/XEe1qq
The vulnerability is due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted EnergyWise packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.
Cisco has released free software updates that address this vulnerability.
There are no workarounds for this vulnerability.
This advisory is available at the following link:
http://bit.ly/XEe1qq
from Cisco Security Advisory http://bit.ly/XEe1qq