CVE-2011-0949
published 2011-05-31CVE-2011-0949: Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.21%
65.1th percentile
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2j4h-p58q-g7mp: Cisco IOS XR 3
ghsa_unreviewed·2022-05-17
CVE-2011-0949 [HIGH] GHSA-2j4h-p58q-g7mp: Cisco IOS XR 3
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
Cisco
Cisco IOS XR Software SSHv1 Denial of Service Vulnerability
vendor_cisco
CVE-2011-0949 Cisco IOS XR Software SSHv1 Denial of Service Vulnerability
CVE-2011-0949: Cisco IOS XR Software SSHv1 Denial of Service Vulnerability
Cisco IOS XR Software contains a vulnerability in the SSH application that may result in a denial of service condition when the SSH version 1 (SSHv1) protocol is used. The vulnerability is a result of unremoved sshd_lock files consuming all available space in the /tmp filesystem. Cisco has released software updates that address this vulnerability. This advisory is posted at� https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110525-iosxr-ssh .
Bug IDs: CSCtd64417, CSCtd74795
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-05-31
Published