>> Cisco IOS Secure Sockets Layer Packets Processing Denial of Service Vulnerabilities
Title : Cisco IOS Secure Sockets Layer Packets Processing Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-1910 CVE ID : CVE-2007-2813
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-22
Technical Description
Multiple vulnerabilities have been identified in Cisco IOS, which could be exploited by remote attackers to cause a denial of service. These issues are caused by errors when processing malformed Secure Sockets Layer (SSL) packets, which could be exploited by remote attackers to crash an affected device and create a denial of service condition by sending a specially crafted "ClientHello", "ChangeCipherSpec", or "Finished" message during the SSL protocol exchange with the vulnerable device.