4.4
CVSSv2

CVE-2013-1219

Published: 29/04/2013 Updated: 01/05/2013
CVSS v2 Base Score: 4.4 | Impact Score: 6.9 | Exploitability Score: 2.7
VMScore: 392
Vector: AV:L/AC:M/Au:S/C:N/I:N/A:C

Vulnerability Summary

Cisco Intrusion Prevention System (IPS) SensorApp contains a vulnerability that could allow a local malicious user to cause a denial of service (DoS) condition. The vulnerability is due to a job failure in the Regex hardware when processing the control transaction getENGVirtualSensorStatistics. A local attacker could exploit the vulnerability by performing an action that uses the getENGVirtualSensorStatistics control transaction. When the malicious action is processed by the affected device, the SensorApp process may hang or become unresponsive to legitimate commands or control transactions, leading to a DoS condition. Cisco has confirmed the vulnerability in a security notice and has released software updates. This vulnerability is applicable only to platforms that implement Regex hardware. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available. To exploit this vulnerability, an attacker requires authenticated access to a targeted device and may require access to trusted, internal networks. These access requirements could limit the likelihood of a successful exploit.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco intrusion prevention system

Vendor Advisories

Cisco Intrusion Prevention System (IPS) SensorApp contains a vulnerability that could allow a local attacker to cause a denial of service (DoS) condition The vulnerability is due to a job failure in the Regex hardware when processing the control transaction getENGVirtualSensorStatistics A local attacker could exploit the vulnerability by perform ...