Cisco IOS Software and Cisco IOS XE Software EnergyWise Crafted Packet Denial of Service Vulnerability

A vulnerability in the EnergyWise module of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of the affected device.



The vulnerability is due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted EnergyWise packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.



Cisco has released free software updates that address this vulnerability.



There are no workarounds for this vulnerability.



This advisory is available at the following link:

http://bit.ly/XEe1qq



from Cisco Security Advisory http://bit.ly/XEe1qq