Vulnerability CVE-2005-0598


Published: 2005-02-24   Modified: 2012-02-12

Description:
The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.

Type:

CWE-Other

Vendor: Cisco
Product: Content engine 
Version:
7325
7320_4.1
7320_4.0
7320_3.1
7320_2.2_.0
7320
590_4.1
590_4.0
590_3.1
590_2.2_.0
590
565
560_4.1
560_4.0
560_3.1
560_2.2_.0
560
510
507_4.1
507_4.0
507_3.1
507_2.2_.0
507
Product: Application and content networking software 
Version:
5.1
5.0.5
5.0.3
5.0.1
5.0
4.2.9
4.2.11
4.2
4.1.3
4.1.1
4.0.3
(acns)
Product: Content delivery manager 
Version: 4650; 4630;
Product: Content distribution manager 4650 
Version: 4.1; 4.0;
Product: Content router 4430 
Version: 4.1; 4.0;
Product: Enterprise content delivery network software 
Version: 4.1; 4.0;
Product: Content distribution manager 4630 
Version: 4.1; 4.0;
Product: Content engine module for cisco router 
Version:
3800_series
3700_series
3600_series
2800_series
2600_series
Product: Content distribution manager 4670 
Product: Content router 4450 

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml
http://www.kb.cert.org/vuls/id/579240
http://www.securityfocus.com/bid/12648
https://exchange.xforce.ibmcloud.com/vulnerabilities/19469

Related CVE
CVE-2019-1915
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco U...
CVE-2019-15272
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerab...
CVE-2019-15259
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that ar...
CVE-2019-15256
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an aff...
CVE-2019-12716
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...
CVE-2019-12715
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...
CVE-2019-12713
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected so...
CVE-2019-12712
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected so...

Copyright 2019, cxsecurity.com

 

Back to Top