Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0257

Опубликовано: 19 апр. 2018
Источник: nvd
CVSS3: 4.3
CVSS2: 3.3
EPSS Низкий

Описание

A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
Версия от 3.18 (включая) до 3.18.4 (включая)
cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
Версия от 16.6 (включая) до 16.6.3 (включая)
cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
Версия от 16.7 (исключая) до 16.7.2 (включая)
cpe:2.3:o:cisco:ios_xe:15.6\(2\)sp:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:16.4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:16.5:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00229
Низкий

4.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-399
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.

EPSS

Процентиль: 45%
0.00229
Низкий

4.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-399
NVD-CWE-noinfo