
====================================================================

                            CERT-Renater

                 Note d'Information No. 2016/VULN104
_____________________________________________________________________

DATE                : 10/03/2016

HARDWARE PLATFORM(S):Cisco Cable Modem with Digital Voice Model DPC2203.

OPERATING SYSTEM(S): Cisco Cable Modem with Digital Voice Model DPC2203
                                software.

======================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160309-cmre
_____________________________________________________________________

Cisco Security Advisory:Cisco Cable Modem with Digital Voice Remote Code 
Execution Vulnerability

Advisory ID: cisco-sa-20160309-cmre

Revision 1.0

Published: 2016 March 9 16:00 GMT
+---------------------------------------------------------------------

Summary
========

A vulnerability in the web server used in the Cisco Cable Modem with
Digital Voice Model DPC2203 could allow an unauthenticated, remote
attacker to exploit a buffer overflow and cause arbitrary code
execution.

The vulnerability is due to improper input validation for HTTP
requests. An attacker could exploit this vulnerability by sending a
crafted HTTP request to the affected device.

Cisco has released software updates to its service provider customers
that address the vulnerability described in this advisory. Prior to
contacting Cisco TAC, customers are advised to contact their service
providers to confirm the software deployed by the service provider
includes the fix that addresses this vulnerability. Workarounds that
mitigate this vulnerability are not available.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160309-cmre

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================



