SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-4910

The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

MEDIUM 5.0EPSS 3.52%

Does this matter?

Lower severity and a low EPSS score (3.52%). Track it; it rarely justifies an emergency change on its own.

Description

The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
3.52% probability · 89th percentile
CISA KEV
Not listed
Affected
cisco/ids sensor software · cisco/ips sensor software
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.