|
|
|
![]() |
Vulnerability Note VU#330275Cisco Content Service Switch reboots when HTTPS POST request is sent to web management interfaceOverviewThe Cisco Content Service Switch contains a denial-of-service vulnerability that allows remote attackers to reboot affected devices.I. DescriptionThe Cisco Content Service Switch (CSS) products include support for the session and application layers. This additional functionality allows a CSS device to make packet switching decisions based on packet contents (such as HTML tags) rather than relying solely upon packet header information.The CSS 11000 series switch contains a vulnerability that causes the device to reboot when an HTTPS POST request is sent to its web management interface. Please note that this vulnerability can be exploited by unauthenticated attackers.
Prevent access to the web management interface Cisco customers who are unable to patch affected devices can limit the exploitation of this vulnerability by preventing access to the web management interface. This can be accomplished via the use of a firewall or by disabling the web management interface from an alternate management interface. Systems Affected
References
This document was written by Jeffrey P. Lanza based on information provided by Cisco Systems.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||