Input validation error in Cisco Mobility Management Entity - CVE-2019-16026

 

Input validation error in Cisco Mobility Management Entity - CVE-2019-16026

Published: January 9, 2020


Vulnerability identifier: #VU24158
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16026
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack on an eNodeB that is connected to an affected device.

The vulnerability exists due to insufficient validation of user-supplied input in the implementation of the Stream Control Transmission Protocol (SCTP). A remote attacker can leverage a man-in-the-middle position between the eNodeB and the MME, then send a specially crafted SCTP message to the MME and cause the MME to stop sending SCTP messages to the eNodeB, results in denial of service condition.


Affected software

Cisco Mobility Management Entity

How to mitigate CVE-2019-16026

Install updates from vendor's website.

Cisco Mobility Management Entity - update to 21.16.1

External References

Related Security Bulletins