Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
Cisco IOS Software를 실행하는 Cisco Integrated Services Module for VPN (ISM-VPN)의 crypto engine에 존재하는 취약점으로 인해 인증되지 않은 원격 공격자가 영향을 받는 장치에서 서비스 거부(DoS) 상태를 유발할 수 있습니다. 이 취약점은 영향을 받는 장치가 VPN 트래픽을 불충분하게 처리하기 때문에 발생합니다. 공격자는 조작된 VPN 트래픽을 영향을 받는 장치로 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 공격자가 영향을 받는 장치를 멈추거나 충돌시켜 DoS 상태를 초래할 수 있습니다. Cisco Bug IDs: CSCvd39267.
Cisco IOS Software를 실행하는 Cisco Integrated Services Module for VPN (ISM-VPN)의 crypto engine에 존재하는 취약점으로 인해 인증되지 않은 원격 공격자가 영향을 받는 장치에서 서비스 거부(DoS) 상태를 유발할 수 있습니다. 이 취약점은 영향을 받는 장치가 VPN 트래픽을 불충분하게 처리하기 때문에 발생합니다. 공격자는 조작된 VPN 트래픽을 영향을 받는 장치로 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 공격자가 영향을 받는 장치를 멈추거나 충돌시켜 DoS 상태를 초래할 수 있습니다. Cisco Bug IDs: CSCvd39267.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.