CVE-2010-0137
published 2010-01-21CVE-2010-0137: Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.85%
85.3th percentile
Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software SSH Denial of Service Vulnerability
vendor_cisco·2010-01-20·CVSS 7.8
CVE-2010-0137 [HIGH] CWE-399 Cisco IOS XR Software SSH Denial of Service Vulnerability
Cisco IOS XR Software SSH Denial of Service Vulnerability
The SSH server implementation in Cisco IOS XR Software contains a
vulnerability that an unauthenticated, remote user could exploit to cause a
denial of service condition.
An attacker could trigger this vulnerability by sending a crafted SSH
version 2 packet that may cause a new SSH connection handler process to crash.
Repeated exploitation may cause each new SSH connection handler process to
crash and lead to a significant amount of memory being consumed, which could
introduce instability that may adversely impact other system functionality.
During this event, the parent SSH daemon process will continue to function
normally.
Cisco has released software updates that address this vulnerability.
This advisory is posted at
https://sec.
Cisco
Cisco IOS XR Software SSH Denial of Service Vulnerability
vendor_cisco
CVE-2010-0137 Cisco IOS XR Software SSH Denial of Service Vulnerability
CVE-2010-0137: Cisco IOS XR Software SSH Denial of Service Vulnerability
The SSH server implementation in Cisco IOS XR Software contains a vulnerability that an unauthenticated, remote user could exploit to cause a denial of service condition. An attacker could trigger this vulnerability by sending a crafted SSH version 2 packet that may cause a new SSH connection handler process to crash. Repeated exploitation may cause each new SSH connection handler process to crash and lead to a significant amount of memory being consumed, which could introduce instability that may adversely impact other system functionality. During this event, the parent SSH daemon process will continue to function normally. Cisco has released software updates that address this vulnerability. This advisory is posted a
GHSA
GHSA-qhpf-56xh-5j88: Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3
ghsa_unreviewed·2022-05-02
CVE-2010-0137 [HIGH] GHSA-qhpf-56xh-5j88: Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3
Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/38227http://securitytracker.com/id?1023480http://www.cisco.com/en/US/products/products_security_advisory09186a0080b13512.shtmlhttp://www.securityfocus.com/bid/37878http://www.vupen.com/english/advisories/2010/0183https://exchange.xforce.ibmcloud.com/vulnerabilities/55767http://secunia.com/advisories/38227http://securitytracker.com/id?1023480http://www.cisco.com/en/US/products/products_security_advisory09186a0080b13512.shtmlhttp://www.securityfocus.com/bid/37878http://www.vupen.com/english/advisories/2010/0183https://exchange.xforce.ibmcloud.com/vulnerabilities/55767
2010-01-21
Published