cbcvebase.

Cisco Staros vulnerabilities

24 known vulnerabilities affecting cisco/staros.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH10MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2019-16026P4MEDIUMCVSS 5.9fixed in 21.16.12020-01-26
CVE-2019-16026 [MEDIUM] CWE-20 CVE-2019-16026: A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mo A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an eNodeB that is connected to an affected device. The vulnerability is due to insufficient input validation of SCTP traffic.
nvd
CVE-2015-0711P4MEDIUMCVSS 5.0v18.1.0.597762015-04-29
CVE-2015-0711 [MEDIUM] CWE-399 CVE-2015-0711: The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5 The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.
nvd
CVE-2015-0712P4MEDIUMCVSS 5.0v12.0v12.2\(300\)+2 more2015-05-01
CVE-2015-0712 [MEDIUM] CWE-399 CVE-2015-0712: The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.
nvd
CVE-2018-0122P4MEDIUMCVSS 4.4v21.3.0.676642018-02-08
CVE-2018-0122 [MEDIUM] CWE-20 CVE-2018-0122: A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregatio A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating syst
nvd
Cisco Staros vulnerabilities | cvebase