Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Network Registrar DNS Denial of Service Vulnerability

cisco-sa-20170419-prime-dns · Medium · Published · Updated

A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected system. The vulnerability is due to incomplete DNS packet header validation when the packet is received by the application. An attacker could exploit this vulnerability by sending a malformed DNS packet to the application. An exploit could allow the attacker to cause the DNS process to restart, which could lead to a DoS condition. Workarounds that address this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170419-prime-dns

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6613
Cisco Bug IDsCSCvb55412
CVSS ScoreBase 5.8
Base 5.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L/E:X/RL:X/RC:X
Product Names From Source
Cisco Prime Network Registrar

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Prime Network Registrar known_affected cisco_csaf CVE-2017-6613 1

Related Products

Product CVE Evidence
Cisco Prime Network CVE-2017-6613 Cisco OpenVuln
Cisco Prime Network Registrar CVE-2017-6613 Cisco OpenVuln