Cisco IC3000 Industrial Compute Gateway Uncontrolled Resource Consumption Vulnerability

Summary

A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Credit:

The information has been provided by Vendor.

The original article can be found at: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-ic3000-icg-dos


Details

The vulnerability exists because the affected software improperly manages system resources. An attacker could exploit this vulnerability by opening a large number of simultaneous sessions on the web-based management interface of an affected device. A successful exploit could allow the attacker to cause a DoS condition of the web-based management interface, preventing normal management operations.

Vulnerable Systems:

Cisco IC3000 Industrial Compute Gateway Software earlier than Release 1.1.1.

CVE Information:

CVE-2019-12714

Disclosure Timeline:

Published Date:10/02/2019