Vulnerability CVE-2008-0536


Published: 2008-05-22   Modified: 2012-02-12

Description:
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Icon-labs -> Iconfidant ssh 
Cisco -> Service control engine 

 References:
http://securitytracker.com/id?1020074
http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml
http://www.icon-labs.com/news/read.asp?newsID=77
http://www.kb.cert.org/vuls/id/626979
http://www.securityfocus.com/bid/29316
http://www.securityfocus.com/bid/29609
http://www.vupen.com/english/advisories/2008/1604/references
http://www.vupen.com/english/advisories/2008/1774/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42566

Copyright 2024, cxsecurity.com

 

Back to Top