TCP Connection Handling Vulnerability in Cisco Remote Expert Manager Software
CVE-2017-6641
What is CVE-2017-6641?
A vulnerability in the TCP connection handling of Cisco Remote Expert Manager Software version 11.0.0 allows an unauthenticated remote attacker to launch a denial-of-service (DoS) attack by disabling TCP ports. Due to insufficient rate-limiting in the TCP Listen application, an attacker can flood the device with specifically crafted TCP packets, including those with the FIN bit set. This exploitation could lead to certain TCP listening ports on the system ceasing to accept connections for an extended period, or until the device is restarted. Additionally, such an attack may exhaust system resources like CPU and memory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Remote Expert Manager Cisco Remote Expert Manager
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved