Vulnerabilities > CVE-2008-1159 - Unspecified vulnerability in Cisco IOS S, IOS T and IOS XR
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cisco
nessus
Summary
Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 3 | |
OS | 1 |
Nessus
NASL family | CISCO |
NASL id | CISCO-SA-20080521-SSHHTTP.NASL |
description | The Secure Shell server (SSH) implementation in Cisco IOS contains multiple vulnerabilities that allow unauthenticated users the ability to generate a spurious memory access error or, in certain cases, reload the device. The IOS SSH server is an optional service that is disabled by default, but its use is highly recommended as a security best practice for management of Cisco IOS devices. SSH can be configured as part of the AutoSecure feature in the initial configuration of IOS devices. AutoSecure runs after initial configuration, or manually. SSH is enabled any time RSA keys are generated such as when a http secure-server or trust points for digital certificates are configured. Devices that are not configured to accept SSH connections are not affected by these vulnerabilities. |
last seen | 2020-03-17 |
modified | 2010-09-01 |
plugin id | 49015 |
published | 2010-09-01 |
reporter | This script is (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/49015 |
title | Cisco IOS Secure Shell Denial of Service Vulnerabilities - Cisco Systems |
code |
|
Oval
accepted | 2008-09-08T04:00:25.774-04:00 | ||||
class | vulnerability | ||||
contributors |
| ||||
description | Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293. | ||||
family | ios | ||||
id | oval:org.mitre.oval:def:5486 | ||||
status | accepted | ||||
submitted | 2008-05-26T11:06:36.000-04:00 | ||||
title | Cisco IOS Secure Shell Denial of Service Vulnerabilities | ||||
version | 3 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 29314 CVE(CAN) ID: CVE-2008-1159 Cisco IOS是思科网络设备中所使用的互联网操作系统。 Cisco IOS中SSH实现的服务端存在多个漏洞,允许未经认证的用户生成伪造的内存访问错误或在某些情况下重载设备。如果攻击者能够重载设备的话,就可以反复利用这些漏洞导致持续的拒绝服务。 IOS SSH服务器是默认禁用的可选服务,但作为管理Cisco IOS设备的最佳安全实践,强烈建议使用这个服务。 Cisco IOS 12.4 临时解决方法: * 应用VTY访问类,仅允许已知的可信任主机通过SSH连接到设备。以下示例允许192.168.1.0/24网段及单个IP地址172.16.1.2对VTY的访问,拒绝任何其他访问: Router(config)# access-list 1 permit 192.168.1.0 0.0.0.255 Router(config)# access-list 1 permit host 172.16.1.2 Router(config)# line vty 0 4 Router(config-line)# access-class 1 in * 部署以下基础架构ACL(iACL) !--- Permit SSH services from trusted hosts destined !--- to infrastructure addresses. access-list 150 permit tcp TRUSTED_HOSTS MASK INFRASTRUCTURE_ADDRESSES MASK eq 22 !--- Deny SSH packets from all other sources destined to infrastructure addresses. access-list 150 deny tcp any INFRASTRUCTURE_ADDRESSES MASK eq 22 !--- Permit all other traffic to transit the device. access-list 150 permit IP any any interface serial 2/0 ip access-group 150 in * 部署以下控制面整型(CoPP) access-list 152 deny tcp TRUSTED_ADDRESSES MASK any eq 22 access-list 152 permit tcp any any eq 22 ! class-map match-all COPP-KNOWN-UNDESIRABLE match access-group 152 ! ! policy-map COPP-INPUT-POLICY class COPP-KNOWN-UNDESIRABLE drop ! control-plane service-policy input COPP-INPUT-POLICY 厂商补丁: Cisco ----- Cisco已经为此发布了一个安全公告(cisco-sa-20080521-ssh)以及相应补丁: cisco-sa-20080521-ssh:Cisco IOS Secure Shell Denial of Service 链接:<a href=http://www.cisco.com/warp/public/707/cisco-sa-20080521-ssh.shtml target=_blank>http://www.cisco.com/warp/public/707/cisco-sa-20080521-ssh.shtml</a> |
id | SSV:3327 |
last seen | 2017-11-19 |
modified | 2008-05-24 |
published | 2008-05-24 |
reporter | Root |
title | Cisco IOS SSH服务器多个拒绝服务漏洞 |
References
- http://secunia.com/advisories/30322
- http://secunia.com/advisories/30322
- http://securitytracker.com/id?1020073
- http://securitytracker.com/id?1020073
- http://www.cisco.com/en/US/products/products_security_advisory09186a008099567f.shtml
- http://www.cisco.com/en/US/products/products_security_advisory09186a008099567f.shtml
- http://www.securityfocus.com/bid/29314
- http://www.securityfocus.com/bid/29314
- http://www.vupen.com/english/advisories/2008/1605/references
- http://www.vupen.com/english/advisories/2008/1605/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42563
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5486
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5486