The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Vulnerability of Cisco IOS, IOS XE: memory leak via Smart Install

Synthesis of the vulnerability

An attacker can create a memory leak via Smart Install of Cisco IOS or IOS XE, in order to trigger a denial of service.
Severity of this computer vulnerability: 2/4.
Creation date: 29/09/2016.
Références of this announce: CERTFR-2016-AVI-322, cisco-sa-20160928-smi, CSCuy82367, CVE-2016-6385, VIGILANCE-VUL-20728.

Description of the vulnerability

The Cisco IOS or IOS XE product has a service to manage received Smart Install (4786/tcp) packets.

However, the memory allocated to process some packets is never freed.

An attacker can therefore create a memory leak via Smart Install of Cisco IOS or IOS XE, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

This vulnerability bulletin impacts software or systems such as Cisco Catalyst, IOS by Cisco, IOS XE Cisco.

Our Vigil@nce team determined that the severity of this security note is medium.

The trust level is of type confirmed by the editor, with an origin of intranet client.

An attacker with a expert ability can exploit this cybersecurity note.

Solutions for this threat

Cisco IOS, IOS XE: solution CSCuy82367.
The solution CSCuy82367 is available:
  https://tools.cisco.com/bugsearch/bug/CSCuy82367
  https://tools.cisco.com/quickview/bug/CSCuy82367
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides a systems vulnerabilities workaround. The technology watch team tracks security threats targeting the computer system.