Denial of service in IBM AIX - CVE-2016-0281

 

Denial of service in IBM AIX - CVE-2016-0281

Published: August 1, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU243
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0281
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the target adapter to crash.

The vulnerability exists in IBM AIX. A remote unauthenticated attacker can trigger a flaw in the mustendd device driver and cause the target IBM AIX FC5899/FC1763 adapter to crash by sending specially crafted packets to the target system.
        
Successful exploitation of this vulnerability may result in denial of service.

Affected software

IBM AIX

How to mitigate CVE-2016-0281

Install the latest versions:

5.3.12: IV84184
6.1.9: IV80569
7.1.3: IV82421
7.1.4: IV81459
7.2.0: IV81357


External References

Related Security Bulletins