SB2020010909 - Denial of service in Cisco Mobility Management Entity



SB2020010909 - Denial of service in Cisco Mobility Management Entity

Published: January 9, 2020

Security Bulletin ID SB2020010909
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2019-16026)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack on an eNodeB that is connected to an affected device.

The vulnerability exists due to insufficient validation of user-supplied input in the implementation of the Stream Control Transmission Protocol (SCTP). A remote attacker can leverage a man-in-the-middle position between the eNodeB and the MME, then send a specially crafted SCTP message to the MME and cause the MME to stop sending SCTP messages to the eNodeB, results in denial of service condition.


Remediation

Install update from vendor's website.