ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

lowAdvisoryimportance 18
AI summary · glm-5.3-flash

Cisco released a fix for a management-plane flooding DoS in IE-1000 switches that can make the device manager, SSH, or API inaccessible.

Insufficient protection against management plane flooding in Cisco Industrial Ethernet 1000 Series Switches allows an unauthenticated remote attacker to send high-rate ICMP, SSH, or HTTP traffic, raising CPU usage and causing a denial-of-service condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates to address the issue.

  • Unauthenticated remote DoS via high-rate ICMP, SSH, or HTTP traffic
  • Only the management plane is affected; data traffic continues
  • Cisco has released fixed software
Full article

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible. This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.