Race Condition in SSL Implementation on Cisco IPS Devices
CVE-2015-0631
Currently unrated
Summary
A race condition found in the SSL implementation of Cisco Intrusion Prevention Systems enables remote attackers to exploit vulnerabilities during the key-regeneration phase of an upgrade. By forcing numerous management-interface HTTPS connections, adversaries can induce a denial of service, potentially disrupting the normal operations of these network security devices.
References
Timeline
Vulnerability published
Vulnerability Reserved