Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5041 | patch vdb entry broken link third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9368 | third party advisory vdb entry |
http://www.cisco.com/warp/public/707/cmts-MD5-bypass-pub.shtml | patch vendor advisory not applicable |