Lucene search

K
ciscoCiscoCISCO-SA-20180328-BFD
HistoryMar 28, 2018 - 4:00 p.m.

Cisco IOS and IOS XE Software Bidirectional Forwarding Detection Denial of Service Vulnerability

2018-03-2816:00:00
tools.cisco.com
71

EPSS

0.004

Percentile

74.9%

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition.

The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd”]

This advisory is part of the March 28, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 20 Cisco Security Advisories that describe 22 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [“https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-66682”].

Affected configurations

Vulners
Node
ciscoiosMatch15.1sg
OR
ciscoiosMatch15.2e
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch3.2sg
OR
ciscocisco_ios_xe_softwareMatch3.3sg
OR
ciscocisco_ios_xe_softwareMatch3.3xo
OR
ciscocisco_ios_xe_softwareMatch3.4sg
OR
ciscocisco_ios_xe_softwareMatch3.5e
OR
ciscocisco_ios_xe_softwareMatch3.6e
OR
ciscocisco_ios_xe_softwareMatch3.7e
OR
ciscocisco_ios_xe_softwareMatch3.8e
OR
ciscocisco_ios_xe_softwareMatch3.9e
OR
ciscocisco_ios_xe_softwareMatch3.10e
OR
ciscocisco_ios_xe_softwareMatchany
OR
ciscoiosMatch15.1\(1\)sg
OR
ciscoiosMatch15.1\(2\)sg
OR
ciscoiosMatch15.1\(1\)sg1
OR
ciscoiosMatch15.1\(1\)sg2
OR
ciscoiosMatch15.1\(2\)sg1
OR
ciscoiosMatch15.1\(2\)sg2
OR
ciscoiosMatch15.1\(2\)sg3
OR
ciscoiosMatch15.1\(2\)sg4
OR
ciscoiosMatch15.1\(2\)sg5
OR
ciscoiosMatch15.1\(2\)sg6
OR
ciscoiosMatch15.1\(2\)sg7
OR
ciscoiosMatch15.1\(2\)sg8
OR
ciscoiosMatch15.2\(1\)e
OR
ciscoiosMatch15.2\(2\)e
OR
ciscoiosMatch15.2\(1\)e1
OR
ciscoiosMatch15.2\(3\)e
OR
ciscoiosMatch15.2\(1\)e3
OR
ciscoiosMatch15.2\(2\)e1
OR
ciscoiosMatch15.2\(2b\)e
OR
ciscoiosMatch15.2\(4\)e
OR
ciscoiosMatch15.2\(3\)e1
OR
ciscoiosMatch15.2\(2\)e2
OR
ciscoiosMatch15.2\(2\)e3
OR
ciscoiosMatch15.2\(3\)e2
OR
ciscoiosMatch15.2\(3\)e3
OR
ciscoiosMatch15.2\(4\)e1
OR
ciscoiosMatch15.2\(2\)e4
OR
ciscoiosMatch15.2\(2\)e5
OR
ciscoiosMatch15.2\(4\)e2
OR
ciscoiosMatch15.2\(3\)e4
OR
ciscoiosMatch15.2\(4\)e3
OR
ciscoiosMatch15.2\(2\)e6
OR
ciscoiosMatch15.2\(2\)e5a
OR
ciscoiosMatch15.2\(3\)e5
OR
ciscoiosMatch15.2\(2\)e5b
OR
ciscoiosMatch15.2\(4\)e4
OR
ciscoiosMatch15.2\(2\)e7
OR
ciscoiosMatch15.2\(4\)e5
OR
ciscoiosMatch15.2\(2\)e7b
OR
ciscoiosMatch15.2\(4\)e5a
OR
ciscoiosMatch15.2\(4s\)e2
OR
ciscoiosMatchany
OR
ciscocisco_ios_xe_softwareMatch3.2.9sg
OR
ciscocisco_ios_xe_softwareMatch3.3.0sg
OR
ciscocisco_ios_xe_softwareMatch3.3.2sg
OR
ciscocisco_ios_xe_softwareMatch3.3.1sg
OR
ciscocisco_ios_xe_softwareMatch3.3.0xo
OR
ciscocisco_ios_xe_softwareMatch3.3.1xo
OR
ciscocisco_ios_xe_softwareMatch3.3.2xo
OR
ciscocisco_ios_xe_softwareMatch3.4.0sg
OR
ciscocisco_ios_xe_softwareMatch3.4.2sg
OR
ciscocisco_ios_xe_softwareMatch3.4.1sg
OR
ciscocisco_ios_xe_softwareMatch3.4.3sg
OR
ciscocisco_ios_xe_softwareMatch3.4.4sg
OR
ciscocisco_ios_xe_softwareMatch3.4.5sg
OR
ciscocisco_ios_xe_softwareMatch3.4.6sg
OR
ciscocisco_ios_xe_softwareMatch3.4.7sg
OR
ciscocisco_ios_xe_softwareMatch3.4.8sg
OR
ciscocisco_ios_xe_softwareMatch3.5.0e
OR
ciscocisco_ios_xe_softwareMatch3.5.1e
OR
ciscocisco_ios_xe_softwareMatch3.5.2e
OR
ciscocisco_ios_xe_softwareMatch3.5.3e
OR
ciscocisco_ios_xe_softwareMatch3.6.0e
OR
ciscocisco_ios_xe_softwareMatch3.6.1e
OR
ciscocisco_ios_xe_softwareMatch3.6.0be
OR
ciscocisco_ios_xe_softwareMatch3.6.2e
OR
ciscocisco_ios_xe_softwareMatch3.6.3e
OR
ciscocisco_ios_xe_softwareMatch3.6.4e
OR
ciscocisco_ios_xe_softwareMatch3.6.5e
OR
ciscocisco_ios_xe_softwareMatch3.6.6e
OR
ciscocisco_ios_xe_softwareMatch3.6.5ae
OR
ciscocisco_ios_xe_softwareMatch3.6.5be
OR
ciscocisco_ios_xe_softwareMatch3.6.7e
OR
ciscocisco_ios_xe_softwareMatch3.7.0e
OR
ciscocisco_ios_xe_softwareMatch3.7.1e
OR
ciscocisco_ios_xe_softwareMatch3.7.2e
OR
ciscocisco_ios_xe_softwareMatch3.7.3e
OR
ciscocisco_ios_xe_softwareMatch3.8.0e
OR
ciscocisco_ios_xe_softwareMatch3.8.1e
OR
ciscocisco_ios_xe_softwareMatch3.8.2e
OR
ciscocisco_ios_xe_softwareMatch3.8.3e
OR
ciscocisco_ios_xe_softwareMatch3.8.4e
OR
ciscocisco_ios_xe_softwareMatch3.8.5e
OR
ciscocisco_ios_xe_softwareMatch3.8.5ae
OR
ciscocisco_ios_xe_softwareMatch3.9.0e
OR
ciscocisco_ios_xe_softwareMatch3.9.1e
OR
ciscocisco_ios_xe_softwareMatch3.9.2e
OR
ciscocisco_ios_xe_softwareMatch3.9.2be
OR
ciscocisco_ios_xe_softwareMatch3.10.0e
OR
ciscocisco_ios_xe_softwareMatch3.10.0ce
OR
ciscocisco_ios_xe_softwareMatchany
VendorProductVersionCPE
ciscoios15.1sgcpe:2.3:o:cisco:ios:15.1sg:*:*:*:*:*:*:*
ciscoios15.2ecpe:2.3:o:cisco:ios:15.2e:*:*:*:*:*:*:*
ciscoiosanycpe:2.3:o:cisco:ios:any:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.2sgcpe:2.3:a:cisco:cisco_ios_xe_software:3.2sg:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.3sgcpe:2.3:a:cisco:cisco_ios_xe_software:3.3sg:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.3xocpe:2.3:a:cisco:cisco_ios_xe_software:3.3xo:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.4sgcpe:2.3:a:cisco:cisco_ios_xe_software:3.4sg:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.5ecpe:2.3:a:cisco:cisco_ios_xe_software:3.5e:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.6ecpe:2.3:a:cisco:cisco_ios_xe_software:3.6e:*:*:*:*:*:*:*
ciscocisco_ios_xe_software3.7ecpe:2.3:a:cisco:cisco_ios_xe_software:3.7e:*:*:*:*:*:*:*
Rows per page:
1-10 of 1031

EPSS

0.004

Percentile

74.9%