Denial of Service Vulnerability in Unisys ClearPath MCP Systems
CVE-2017-5872
7.5HIGH
What is CVE-2017-5872?
The TCP/IP networking module in Unisys ClearPath MCP systems is susceptible to a Denial of Service vulnerability when running a TLS 1.2 service. Attackers can exploit this weakness by sending a specially crafted client hello message with a signature_algorithms extension that exceeds the limits specified in RFC 5246. This manipulation can result in a full memory dump and disrupt network connectivity, affecting the system's performance and availability.
