Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0170

Опубликовано: 28 мар. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been freed. An attacker could exploit this vulnerability by sending crafted, malformed IP packets to an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvb86327.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:cisco:ios_xe:16.4.1:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01965
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been freed. An attacker could exploit this vulnerability by sending crafted, malformed IP packets to an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvb86327.

EPSS

Процентиль: 83%
0.01965
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-416
CWE-416