Vulnerability CVE-2006-0354


Published: 2006-01-22   Modified: 2012-02-12

Description:
Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Access Point Memory Exhaustion from ARP Attacks
CISCO
13.01.2006

Vendor: Cisco
Product: Aironet ap1300 
Product: Aironet ap1100 
Product: Aironet ap350 
Product: Aironet ap1200 
Product: Aironet ap1240ag 
Product: Aironet ap1400 
Product: Aironet ap1130ag 
Product: Aironet ap1230ag 

CVSS2 => (AV:A/AC:L/Au:S/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
6.9/10
5.1/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete

 References:
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5680
http://securityreason.com/securityalert/339
http://securitytracker.com/id?1015483
http://www.cisco.com/warp/public/707/cisco-sa-20060112-wireless.shtml
http://www.securityfocus.com/bid/16217
http://www.vupen.com/english/advisories/2006/0176
https://exchange.xforce.ibmcloud.com/vulnerabilities/24086

Related CVE
CVE-2019-1794
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this ...
CVE-2019-1712
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device. The vu...
CVE-2019-1711
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling o...
CVE-2019-1686
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected ...
CVE-2018-7340
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing...
CVE-2019-1786
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected ...
CVE-2019-1762
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed...
CVE-2019-1761
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to i...

Copyright 2019, cxsecurity.com

 

Back to Top