Cisco Ios Software Ip Service Level Agreement Denial Of Service Vulnerability

Customers who purchase directly from Cisco but do not have a Cisco service contract and customers who purchase third-party software but do not receive fixed software through their point of sale should receive upgrades to cisco TAC: Is there any known malware that exploits this vulnerability? The vulnerability lies in the ip service level agreement (SLA) function that could use a port that could be used by another feature. A remote attacker can send certain SLA IP control packages and cause the consumption of a port used by the IP-SLA answering machine, resulting in a denial of service condition. Cisco has released software updates that fix this vulnerability. There is no workaround to address this security vulnerability. It is known that only the products listed in the “Vulnerable Products” section of this recommendation are affected by this vulnerability. This recommendation is available on the following link: customers must ensure that the devices to be updated contain enough memory and confirm that current hardware and software configurations continue to be properly supported by the new version. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their mandated maintenance providers. Tenable calculates a dynamic VPR for each weak point. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Learn more about what VPR is and how it differs from CVSS.

Security vulnerability allows a remote attacker to report a doS (denial of service) attack. For more information on Cisco`s security disclosure policies and publications, see the Security Vulnerability Directive.