Input validation error in Cisco Mobility Management Entity - CVE-2019-16026
Published: January 9, 2020
Cisco Mobility Management Entity
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack on an eNodeB that is connected to an affected device.
The vulnerability exists due to insufficient validation of user-supplied input in the implementation of the Stream Control Transmission Protocol (SCTP). A remote attacker can leverage a man-in-the-middle
position between the eNodeB and the MME, then send a specially crafted SCTP
message to the MME and cause the MME to stop
sending SCTP messages to the eNodeB, results in denial of service condition.