CVE-2010-2827
published 2010-08-16CVE-2010-2827: Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TCP outage) via spoofed TCP packets, related to embryonic TCP…
high7.8CVSS 3.1
AVNACLAuNCNINAC
Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TCP outage) via spoofed TCP packets, related to embryonic TCP connections that remain in the SYN_RCVD or SYN_SENT state, aka Bug ID CSCti18193.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
Cisco
Cisco IOS Software TCP Denial of Service Vulnerability
vendor_cisco·2010-08-12·CVSS 7.8
CVE-2010-2827 [HIGH] CWE-399 Cisco IOS Software TCP Denial of Service Vulnerability
Cisco IOS Software TCP Denial of Service Vulnerability
Cisco IOS® Software Release, 15.1(2)T is
affected by a denial of service (DoS) vulnerability during the TCP
establishment phase. The vulnerability could cause embryonic TCP connections to
remain in a SYNRCVD or SYNSENT state. Enough embryonic TCP connections in these
states could consume system resources and prevent an affected device from
accepting or initiating new TCP connections, including any TCP-based remote
management access to the device.
No authentication is required to exploit this vulnerability. An
attacker does not need to complete a three-way handshake to trigger this
vulnerability; therefore, this vulnerability can be exploited using spoofed
packets. This vulnerability may be triggered by normal network traffic.
Cisco ha
Cisco
Cisco IOS Software TCP Denial of Service Vulnerability
vendor_cisco
CVE-2010-2827 Cisco IOS Software TCP Denial of Service Vulnerability
CVE-2010-2827: Cisco IOS Software TCP Denial of Service Vulnerability
Cisco IOS � Software Release, 15.1(2)T is affected by a denial of service (DoS) vulnerability during the TCP establishment phase. The vulnerability could cause embryonic TCP connections to remain in a SYNRCVD or SYNSENT state. Enough embryonic TCP connections in these states could consume system resources and prevent an affected device from accepting or initiating new TCP connections, including any TCP-based remote management access to the device. No authentication is required to exploit this vulnerability. An attacker does not need to complete a three-way handshake to trigger this vulnerability; therefore, this vulnerability can be exploited using spoofed packets. This vulnerability may be triggered by normal network tr
GHSA
GHSA-fggf-4pc6-vrvf: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2010-2827 [HIGH] CWE-20 GHSA-fggf-4pc6-vrvf: Cisco IOS 15
Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TCP outage) via spoofed TCP packets, related to embryonic TCP connections that remain in the SYN_RCVD or SYN_SENT state, aka Bug ID CSCti18193.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-08-16
Published