Vulnslist

find the latest Cisco vulnerabilities

Cisco Service Control Engine Denial of Service Vulnerabilities

cisco-sa-20080521-sce · High · Published · Updated

Three Secure Shell (SSH) vulnerabilities exist in the Cisco Service Control Engine (SCE) that may result in system instability or a reload of the SCE. The first vulnerability may be triggered during SSH login activity that is conducted within aggressive time frames. The second vulnerability may be triggered with normal SSH login activity in combination with other SCE management actions occurring simultaneously. The third vulnerability may be triggered during SSH login and is specific to the usage of unique invalid authentication credentials. Cisco has made free upgrade software available to address these vulnerabilities for affected customers. There are no workarounds for these vulnerabilities. Note: These vulnerabilities are independent of each other; a device may be affected by one vulnerability and not by the others. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080521-sce.

Workarounds

No workaround information imported yet.

CVEsCVE-2008-0534, CVE-2008-0535, CVE-2008-0536
Cisco Bug IDsNA
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco Service Control Engine (SCE)

Related Products

Product CVE Evidence
Cisco Service Control Engine (SCE) CVE-2008-0536 Cisco OpenVuln
Cisco Service Control Engine (SCE) CVE-2008-0535 Cisco OpenVuln
Cisco Service Control Engine (SCE) CVE-2008-0534 Cisco OpenVuln