Vulnerability Description
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | 3.6.0 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f18f.sVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f18f.sVendor Advisory
FAQ
What is CVE-2011-0949?
CVE-2011-0949 is a vulnerability with a CVSS score of 7.8 (HIGH). Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by mak...
How severe is CVE-2011-0949?
CVE-2011-0949 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0949?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr.