Lucene search

K
ciscoCiscoCISCO-SA-20140924-DHCPV6
HistorySep 24, 2014 - 4:00 p.m.

Cisco IOS Software DHCP Version 6 Denial of Service Vulnerability

2014-09-2416:00:00
tools.cisco.com
28

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.013

Percentile

85.8%

A vulnerability in the DHCP version 6 (DHCPv6) server implementation of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability is due to improper parsing of malformed DHCPv6 packets. An attacker could exploit this vulnerability by sending malformed DHCPv6 packets to be processed by an affected device. An exploit could allow the attacker to cause a memory leak and eventual reload of an affected device.

Cisco has released software updates that address this vulnerability. This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-dhcpv6[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-dhcpv6”]

Note: The September 24, 2014, Cisco IOS Software Security Advisory bundled publication includes six Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Individual publication links are in Cisco Event Response: Semiannual Cisco IOS Software Security Advisory Bundled Publication at the following link:
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep14.html[“http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep14.html”]

Affected configurations

Vulners
Node
ciscoiosMatch15.2s
OR
ciscoiosMatch15.1s
OR
ciscoiosMatch15.3s
OR
ciscoiosMatch15.4t
OR
ciscoiosMatch15.1mra
OR
ciscoiosMatch15.4s
OR
ciscoiosMatch15.3m
OR
ciscoiosMatch15.2sc
OR
ciscoiosMatch15.3xb
OR
ciscoiosMatch15.4cg
OR
ciscoiosMatch15.1svs
OR
ciscoiosMatch15.1svt
OR
ciscoiosMatch15.1svu
OR
ciscoiosMatch15.1svv
OR
ciscoiosMatch15.1svw
OR
ciscoiosMatch15.1svx
OR
ciscocisco_iosMatch3.7sxe
OR
ciscocisco_iosMatch3.8sxe
OR
ciscocisco_iosMatch3.9sxe
OR
ciscocisco_iosMatch3.10sxe
OR
ciscocisco_iosMatch3.11sxe
OR
ciscoiosMatch15.2\(1\)s
OR
ciscoiosMatch15.2\(2\)s
OR
ciscoiosMatch15.2\(1\)s1
OR
ciscoiosMatch15.2\(4\)s
OR
ciscoiosMatch15.2\(1\)s2
OR
ciscoiosMatch15.2\(2\)s1
OR
ciscoiosMatch15.2\(2\)s2
OR
ciscoiosMatch15.2\(2\)s0a
OR
ciscoiosMatch15.2\(2\)s0c
OR
ciscoiosMatch15.2\(2\)s0d
OR
ciscoiosMatch15.2\(4\)s1
OR
ciscoiosMatch15.2\(4\)s4
OR
ciscoiosMatch15.2\(4\)s2
OR
ciscoiosMatch15.2\(4\)s5
OR
ciscoiosMatch15.2\(4\)s3
OR
ciscoiosMatch15.2\(4\)s0c
OR
ciscoiosMatch15.2\(4\)s1c
OR
ciscoiosMatch15.2\(4\)s3a
OR
ciscoiosMatch15.2\(4\)s4a
OR
ciscoiosMatch15.1\(3\)s
OR
ciscoiosMatch15.1\(3\)s1
OR
ciscoiosMatch15.1\(3\)s0a
OR
ciscoiosMatch15.1\(3\)s2
OR
ciscoiosMatch15.1\(3\)s4
OR
ciscoiosMatch15.1\(3\)s3
OR
ciscoiosMatch15.1\(3\)s5
OR
ciscoiosMatch15.1\(3\)s6
OR
ciscoiosMatch15.1\(3\)s5a
OR
ciscoiosMatch15.3\(1\)s
OR
ciscoiosMatch15.3\(2\)s
OR
ciscoiosMatch15.3\(3\)s
OR
ciscoiosMatch15.3\(1\)s2
OR
ciscoiosMatch15.3\(1\)s1
OR
ciscoiosMatch15.3\(2\)s2
OR
ciscoiosMatch15.3\(2\)s1
OR
ciscoiosMatch15.3\(1\)s1e
OR
ciscoiosMatch15.3\(3\)s1
OR
ciscoiosMatch15.3\(3\)s2
OR
ciscoiosMatch15.3\(3\)s3
OR
ciscoiosMatch15.3\(3\)s1a
OR
ciscoiosMatch15.3\(3\)s2a
OR
ciscoiosMatch15.4\(1\)t
OR
ciscoiosMatch15.4\(2\)t
OR
ciscoiosMatch15.4\(1\)t1
OR
ciscoiosMatch15.1\(3\)mra
OR
ciscoiosMatch15.1\(3\)mra1
OR
ciscoiosMatch15.1\(3\)mra2
OR
ciscoiosMatch15.1\(3\)mra4
OR
ciscoiosMatch15.4\(1\)s
OR
ciscoiosMatch15.4\(1\)s1
OR
ciscoiosMatch15.4\(1\)s2
OR
ciscoiosMatch15.3\(3\)m
OR
ciscoiosMatch15.3\(3\)m1
OR
ciscoiosMatch15.3\(3\)m2
OR
ciscoiosMatch15.3\(3\)m3
OR
ciscoiosMatch15.2\(2\)sc3
OR
ciscoiosMatch15.3\(3\)xb12
OR
ciscoiosMatch15.4\(1\)cg
OR
ciscoiosMatch15.4\(1\)cg1
OR
ciscoiosMatch15.4\(2\)cg
OR
ciscoiosMatch15.1\(3\)svs
OR
ciscoiosMatch15.1\(3\)svt1
OR
ciscoiosMatch15.1\(3\)svt3
OR
ciscoiosMatch15.1\(3\)svt4
OR
ciscoiosMatch15.1\(3\)svu1
OR
ciscoiosMatch15.1\(3\)svu10
OR
ciscoiosMatch15.1\(3\)svu2
OR
ciscoiosMatch15.1\(3\)svu11
OR
ciscoiosMatch15.1\(3\)svu21
OR
ciscoiosMatch15.1\(3\)svv1
OR
ciscoiosMatch15.1\(3\)svv2
OR
ciscoiosMatch15.1\(3\)svv3
OR
ciscoiosMatch15.1\(3\)svv4
OR
ciscoiosMatch15.1\(3\)svw
OR
ciscoiosMatch15.1\(3\)svw1
OR
ciscoiosMatch15.1\(3\)svx
OR
ciscoiosMatch15.1\(3\)svx1
OR
ciscocisco_iosMatch3.7.0sxe
OR
ciscocisco_iosMatch3.7.1sxe
OR
ciscocisco_iosMatch3.7.2sxe
OR
ciscocisco_iosMatch3.7.3sxe
OR
ciscocisco_iosMatch3.7.4sxe
OR
ciscocisco_iosMatch3.7.5sxe
OR
ciscocisco_iosMatch3.7.4asxe
OR
ciscocisco_iosMatch3.7.2tsxe
OR
ciscocisco_iosMatch3.7.0bsxe
OR
ciscocisco_iosMatch3.7.1asxe
OR
ciscocisco_iosMatch3.8.0sxe
OR
ciscocisco_iosMatch3.8.1sxe
OR
ciscocisco_iosMatch3.8.2sxe
OR
ciscocisco_iosMatch3.9.1sxe
OR
ciscocisco_iosMatch3.9.0sxe
OR
ciscocisco_iosMatch3.9.2sxe
OR
ciscocisco_iosMatch3.9.1asxe
OR
ciscocisco_iosMatch3.9.0asxe
OR
ciscocisco_iosMatch3.10.0sxe
OR
ciscocisco_iosMatch3.10.1sxe
OR
ciscocisco_iosMatch3.10.2sxe
OR
ciscocisco_iosMatch3.10.3sxe
OR
ciscocisco_iosMatch3.10.1xcsxe
OR
ciscocisco_iosMatch3.10.2asxe
OR
ciscocisco_iosMatch3.10.2tsxe
OR
ciscocisco_iosMatch3.10.1xbsxe
OR
ciscocisco_iosMatch3.11.1sxe
OR
ciscocisco_iosMatch3.11.2sxe
OR
ciscocisco_iosMatch3.11.0sxe
VendorProductVersionCPE
ciscoios15.2scpe:2.3:o:cisco:ios:15.2s:*:*:*:*:*:*:*
ciscoios15.1scpe:2.3:o:cisco:ios:15.1s:*:*:*:*:*:*:*
ciscoios15.3scpe:2.3:o:cisco:ios:15.3s:*:*:*:*:*:*:*
ciscoios15.4tcpe:2.3:o:cisco:ios:15.4t:*:*:*:*:*:*:*
ciscoios15.1mracpe:2.3:o:cisco:ios:15.1mra:*:*:*:*:*:*:*
ciscoios15.4scpe:2.3:o:cisco:ios:15.4s:*:*:*:*:*:*:*
ciscoios15.3mcpe:2.3:o:cisco:ios:15.3m:*:*:*:*:*:*:*
ciscoios15.2sccpe:2.3:o:cisco:ios:15.2sc:*:*:*:*:*:*:*
ciscoios15.3xbcpe:2.3:o:cisco:ios:15.3xb:*:*:*:*:*:*:*
ciscoios15.4cgcpe:2.3:o:cisco:ios:15.4cg:*:*:*:*:*:*:*
Rows per page:
1-10 of 1271

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.013

Percentile

85.8%

Related for CISCO-SA-20140924-DHCPV6