>> Cisco Service Control Engine Multiple Denial of Service Vulnerabilities
Title : Cisco Service Control Engine Multiple Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1604 CVE ID : CVE-2008-0534 - CVE-2008-0535 - CVE-2008-0536
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-21
Technical Description
Multiple vulnerabilities have been identified in Cisco Service Control Engine (SCE), which could be exploited by attackers to cause a denial of service.
The first issue is caused by an unspecified error in the Secure Shell (SSH) server when handling login attempts, which may result in system instability, temporary resource unavailability, or a reload of the device.
The second vulnerability is caused by illegal Input/Output operations in the SCE management interface when handling SSH traffic, which may result in the loss of management access.
The third vulnerability is caused by an error in the SSH server when handling specific credentials that attempt to change the authentication method, which may result in system instability.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.