Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0480

Опубликовано: 05 окт. 2018
Источник: nvd
CVSS3: 6.1
CVSS2: 5.7
EPSS Низкий

Описание

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:cisco:ios_xe:3.6\(5\):*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00169
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2

Дефекты

CWE-362
CWE-362

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.

CVSS3: 7.4
fstec
больше 7 лет назад

Уязвимость функции per-VLAN errdisable операционной системы Cisco IOS XE, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00169
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2

Дефекты

CWE-362
CWE-362