Cisco 3000 Series Industrial Security Appliances(ISR)等都是美国思科(Cisco)公司的安全防火墙设备。Firepower System Software是使用在其中的一套防火墙软件。 多款Cisco产品中的Firepower System Software 6.0.1版本、6.1.0版本、6.2.0版本和6.2.1版本的检测引擎解析IPv6数据包的过程存在安全漏洞,该漏洞源于程序没有对IPv6扩展包头数据包中的字段执行输入验证。远程攻击者可通过向检测引擎发送恶意的IPv6数据包利用该漏洞造成拒绝服务(CPU大量占用)。以下产品受到影响:Cisco 3000 Series Industrial Security Appliances (ISR);Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services;Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls;Advanced Malware Protection (AMP) for Networks;7000 Series Appliances;Advanced Malware Protection (AMP) for Networks;8000 Series Appliances;FirePOWER 7000 Series Appliances;FirePOWER 8000 Series Appliances;Firepower Threat Defense for Integrated Services Routers (ISRs);Firepower 2100 Series Security Appliances;Firepower 4100 Series Security Appliances;Firepower 9300 Series Security Appliances;Virtual Next-Generation Intrusion Prevention System (NGIPSv) for VMware。
Cisco 3000 Series Industrial Security Appliances(ISR)等都是美国思科(Cisco)公司的安全防火墙设备。Firepower System Software是使用在其中的一套防火墙软件。 多款Cisco产品中的Firepower System Software 6.0.1版本、6.1.0版本、6.2.0版本和6.2.1版本的检测引擎解析IPv6数据包的过程存在安全漏洞,该漏洞源于程序没有对IPv6扩展包头数据包中的字段执行输入验证。远程攻击者可通过向检测引擎发送恶意的IPv6数据包利用该漏洞造成拒绝服务(CPU大量占用)。以下产品受到影响:Cisco 3000 Series Industrial Security Appliances (ISR);Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services;Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls;Advanced Malware Protection (AMP) for Networks;7000 Series Appliances;Advanced Malware Protection (AMP) for Networks;8000 Series Appliances;FirePOWER 7000 Series Appliances;FirePOWER 8000 Series Appliances;Firepower Threat Defense for Integrated Services Routers (ISRs);Firepower 2100 Series Security Appliances;Firepower 4100 Series Security Appliances;Firepower 9300 Series Security Appliances;Virtual Next-Generation Intrusion Prevention System (NGIPSv) for VMware。