漏洞类别:Cisco
漏洞等级:
漏洞信息
A vulnerability in the Internet Key Exchange version 2 (IKEv2) code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause a reload of the affected device.
The vulnerability is due to improper handling of crafted IKEv2 packets. The vulnerability applies only to IKEv2 devices acting as clients or IKEv2 initiators.
漏洞危害
An attacker could exploit this vulnerability by sending crafted packets to the affected devices. An attacker, however, would need to be able to force the affected device to connect to a rogue IKEv2 server under its control. An exploit could allow the attacker to cause a reload of the affected system.
解决方案
Refer to Cisco advisory cisco-sa-20161005-ios-ikev for updates and patch information.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
0day
文章评论