Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w837-qm63-r5ph

Опубликовано: 23 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel interface or on a physical interface that is configured with a maximum transmission unit (MTU) greater than 4,615 bytes. An attacker could exploit this vulnerability by sending fragmented packets through a VFR-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel interface or on a physical interface that is configured with a maximum transmission unit (MTU) greater than 4,615 bytes. An attacker could exploit this vulnerability by sending fragmented packets through a VFR-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

EPSS

Процентиль: 75%
0.00902
Низкий

8.6 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.6
nvd
почти 3 года назад

A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel interface or on a physical interface that is configured with a maximum transmission unit (MTU) greater than 4,615 bytes. An attacker could exploit this vulnerability by sending fragmented packets through a VFR-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

CVSS3: 8.6
fstec
почти 3 года назад

Уязвимость функции IPv4 Virtual Fragmentation Reassembly (VFR) операционных систем Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании или вызвать перезагрузку устройства

EPSS

Процентиль: 75%
0.00902
Низкий

8.6 High

CVSS3

Дефекты

CWE-416