SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2824

Unspecified vulnerability on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2(2.x) before A2(2.3), and A2(3.x) before A2(3.1) for Catalyst 6500 series switches and 7600 series routers allows remote attackers to…

HIGH 7.8EPSS 1.76%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unspecified vulnerability on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2(2.x) before A2(2.3), and A2(3.x) before A2(3.1) for Catalyst 6500 series switches and 7600 series routers allows remote attackers to cause a denial of service (device reload) via a sequence of SSL packets, aka Bug ID CSCta20756.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
1.76% probability · 77th percentile
CISA KEV
Not listed
Affected
cisco/ace module
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.