Race Condition in SSL Implementation on Cisco IPS Devices
CVE-2015-0631

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 February 2015

Summary

A race condition found in the SSL implementation of Cisco Intrusion Prevention Systems enables remote attackers to exploit vulnerabilities during the key-regeneration phase of an upgrade. By forcing numerous management-interface HTTPS connections, adversaries can induce a denial of service, potentially disrupting the normal operations of these network security devices.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.