Lucene search

K
ciscoCiscoCISCO-SA-20180328-SMI2
HistoryMar 28, 2018 - 4:00 p.m.

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

2018-03-2816:00:00
tools.cisco.com
507

EPSS

0.851

Percentile

98.5%

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device.

The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts:

Triggering a reload of the device
Allowing the attacker to execute arbitrary code on the device
Causing an indefinite loop on the affected device that triggers a watchdog crash

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Smart Install client functionality is enabled by default on switches that are running Cisco IOS Software releases that have not been updated to address Cisco bug ID CSCvd36820 [“https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd36820”].

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2”]

This advisory is part of the March 28, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 20 Cisco Security Advisories that describe 22 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [“https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-66682”].

Affected configurations

Vulners
Node
ciscoiosMatch12.2se
OR
ciscoiosMatch12.2ex
OR
ciscoiosMatch12.2ey
OR
ciscoiosMatch12.2ez
OR
ciscoiosMatch15.0ey
OR
ciscoiosMatch15.0se
OR
ciscoiosMatch15.1sg
OR
ciscoiosMatch15.0ex
OR
ciscoiosMatch15.0ea
OR
ciscoiosMatch15.2e
OR
ciscoiosMatch15.0ez
OR
ciscoiosMatch15.2ey
OR
ciscoiosMatch15.0ej
OR
ciscoiosMatch15.2ex
OR
ciscoiosMatch15.2jaz
OR
ciscoiosMatch15.2eb
OR
ciscoiosMatch15.2ea
OR
ciscoiosMatch15.2ec
OR
ciscoiosMatch15.3jpi
OR
ciscoiosMatch15.3jpj
OR
ciscoiosMatch15.3jpr
OR
ciscocisco_ios_xe_softwareMatch3.2se
OR
ciscocisco_ios_xe_softwareMatch3.3se
OR
ciscocisco_ios_xe_softwareMatch3.3xo
OR
ciscocisco_ios_xe_softwareMatch3.4sg
OR
ciscocisco_ios_xe_softwareMatch3.5e
OR
ciscocisco_ios_xe_softwareMatch3.6e
OR
ciscocisco_ios_xe_softwareMatch3.7e
OR
ciscocisco_ios_xe_softwareMatch16.1
OR
ciscocisco_ios_xe_softwareMatch16.2
OR
ciscocisco_ios_xe_softwareMatch3.8e
OR
ciscocisco_ios_xe_softwareMatch16.3
OR
ciscocisco_ios_xe_softwareMatch16.4
OR
ciscocisco_ios_xe_softwareMatch16.5
OR
ciscocisco_ios_xe_softwareMatch3.9e
OR
ciscocisco_ios_xe_softwareMatch16.6
OR
ciscocisco_ios_xe_softwareMatch3.10e
OR
ciscoiosMatch12.2\(55\)se
OR
ciscoiosMatch12.2\(55\)se3
OR
ciscoiosMatch12.2\(55\)se2
OR
ciscoiosMatch12.2\(58\)se
OR
ciscoiosMatch12.2\(55\)se1
OR
ciscoiosMatch12.2\(58\)se1
OR
ciscoiosMatch12.2\(55\)se4
OR
ciscoiosMatch12.2\(58\)se2
OR
ciscoiosMatch12.2\(55\)se5
OR
ciscoiosMatch12.2\(55\)se6
OR
ciscoiosMatch12.2\(55\)se7
OR
ciscoiosMatch12.2\(55\)se8
OR
ciscoiosMatch12.2\(55\)se9
OR
ciscoiosMatch12.2\(55\)se10
OR
ciscoiosMatch12.2\(55\)se11
OR
ciscoiosMatch12.2\(55\)se12
OR
ciscoiosMatch12.2\(55\)ex
OR
ciscoiosMatch12.2\(55\)ex1
OR
ciscoiosMatch12.2\(55\)ex2
OR
ciscoiosMatch12.2\(55\)ex3
OR
ciscoiosMatch12.2\(55\)ey
OR
ciscoiosMatch12.2\(55\)ez
OR
ciscoiosMatch15.0\(1\)ey
OR
ciscoiosMatch15.0\(1\)ey2
OR
ciscoiosMatch15.0\(1\)se
OR
ciscoiosMatch15.0\(2\)se
OR
ciscoiosMatch15.0\(1\)se1
OR
ciscoiosMatch15.0\(1\)se2
OR
ciscoiosMatch15.0\(1\)se3
OR
ciscoiosMatch15.0\(2\)se1
OR
ciscoiosMatch15.0\(2\)se2
OR
ciscoiosMatch15.0\(2\)se3
OR
ciscoiosMatch15.0\(2\)se4
OR
ciscoiosMatch15.0\(2\)se5
OR
ciscoiosMatch15.0\(2\)se6
OR
ciscoiosMatch15.0\(2\)se7
OR
ciscoiosMatch15.0\(2\)se8
OR
ciscoiosMatch15.0\(2\)se9
OR
ciscoiosMatch15.0\(2a\)se9
OR
ciscoiosMatch15.0\(2\)se10
OR
ciscoiosMatch15.0\(2\)se11
OR
ciscoiosMatch15.0\(2\)se10a
OR
ciscoiosMatch15.1\(2\)sg
OR
ciscoiosMatch15.1\(2\)sg1
OR
ciscoiosMatch15.1\(2\)sg2
OR
ciscoiosMatch15.1\(2\)sg3
OR
ciscoiosMatch15.1\(2\)sg4
OR
ciscoiosMatch15.1\(2\)sg5
OR
ciscoiosMatch15.1\(2\)sg6
OR
ciscoiosMatch15.1\(2\)sg7
OR
ciscoiosMatch15.1\(2\)sg8
OR
ciscoiosMatch15.0\(2\)ex
OR
ciscoiosMatch15.0\(2\)ex1
OR
ciscoiosMatch15.0\(2\)ex2
OR
ciscoiosMatch15.0\(2\)ex3
OR
ciscoiosMatch15.0\(2\)ex4
OR
ciscoiosMatch15.0\(2\)ex5
OR
ciscoiosMatch15.0\(2\)ex6
OR
ciscoiosMatch15.0\(2\)ex7
OR
ciscoiosMatch15.0\(2\)ex8
OR
ciscoiosMatch15.0\(2a\)ex5
OR
ciscoiosMatch15.0\(2\)ex10
OR
ciscoiosMatch15.0\(2\)ex11
OR
ciscoiosMatch15.0\(2\)ex13
OR
ciscoiosMatch15.0\(2\)ex12
OR
ciscoiosMatch15.0\(2\)ea1
OR
ciscoiosMatch15.2\(1\)e
OR
ciscoiosMatch15.2\(2\)e
OR
ciscoiosMatch15.2\(1\)e1
OR
ciscoiosMatch15.2\(3\)e
OR
ciscoiosMatch15.2\(1\)e2
OR
ciscoiosMatch15.2\(1\)e3
OR
ciscoiosMatch15.2\(2\)e1
OR
ciscoiosMatch15.2\(2b\)e
OR
ciscoiosMatch15.2\(4\)e
OR
ciscoiosMatch15.2\(3\)e1
OR
ciscoiosMatch15.2\(2\)e2
OR
ciscoiosMatch15.2\(2a\)e1
OR
ciscoiosMatch15.2\(2\)e3
OR
ciscoiosMatch15.2\(2a\)e2
OR
ciscoiosMatch15.2\(3\)e2
OR
ciscoiosMatch15.2\(3a\)e
OR
ciscoiosMatch15.2\(3\)e3
OR
ciscoiosMatch15.2\(3m\)e2
OR
ciscoiosMatch15.2\(4\)e1
OR
ciscoiosMatch15.2\(2\)e4
OR
ciscoiosMatch15.2\(2\)e5
OR
ciscoiosMatch15.2\(4\)e2
OR
ciscoiosMatch15.2\(4m\)e1
OR
ciscoiosMatch15.2\(3\)e4
OR
ciscoiosMatch15.2\(5\)e
OR
ciscoiosMatch15.2\(3m\)e7
OR
ciscoiosMatch15.2\(4\)e3
OR
ciscoiosMatch15.2\(2\)e6
OR
ciscoiosMatch15.2\(5a\)e
OR
ciscoiosMatch15.2\(5\)e1
OR
ciscoiosMatch15.2\(5b\)e
OR
ciscoiosMatch15.2\(4m\)e3
OR
ciscoiosMatch15.2\(3m\)e8
OR
ciscoiosMatch15.2\(2\)e5a
OR
ciscoiosMatch15.2\(5c\)e
OR
ciscoiosMatch15.2\(3\)e5
OR
ciscoiosMatch15.2\(2\)e5b
OR
ciscoiosMatch15.2\(4n\)e2
OR
ciscoiosMatch15.2\(4o\)e2
OR
ciscoiosMatch15.2\(5a\)e1
OR
ciscoiosMatch15.2\(4\)e4
OR
ciscoiosMatch15.2\(2\)e7
OR
ciscoiosMatch15.2\(5\)e2
OR
ciscoiosMatch15.2\(4p\)e1
OR
ciscoiosMatch15.2\(6\)e
OR
ciscoiosMatch15.2\(5\)e2b
OR
ciscoiosMatch15.2\(4\)e5
OR
ciscoiosMatch15.2\(5\)e2c
OR
ciscoiosMatch15.2\(4m\)e2
OR
ciscoiosMatch15.2\(4o\)e3
OR
ciscoiosMatch15.2\(4q\)e1
OR
ciscoiosMatch15.2\(6\)e0a
OR
ciscoiosMatch15.2\(2\)e7b
OR
ciscoiosMatch15.2\(4\)e5a
OR
ciscoiosMatch15.2\(6\)e0c
OR
ciscoiosMatch15.2\(4s\)e1
OR
ciscoiosMatch15.2\(4s\)e2
OR
ciscoiosMatch15.0\(2\)ez
OR
ciscoiosMatch15.2\(1\)ey
OR
ciscoiosMatch15.0\(2\)ej
OR
ciscoiosMatch15.0\(2\)ej1
OR
ciscoiosMatch15.2\(5\)ex
OR
ciscoiosMatch15.2\(4\)jaz1
OR
ciscoiosMatch15.2\(2\)eb
OR
ciscoiosMatch15.2\(2\)eb1
OR
ciscoiosMatch15.2\(2\)eb2
OR
ciscoiosMatch15.2\(2\)ea
OR
ciscoiosMatch15.2\(2\)ea1
OR
ciscoiosMatch15.2\(2\)ea2
OR
ciscoiosMatch15.2\(3\)ea
OR
ciscoiosMatch15.2\(4\)ea
OR
ciscoiosMatch15.2\(4\)ea1
OR
ciscoiosMatch15.2\(2\)ea3
OR
ciscoiosMatch15.2\(4\)ea3
OR
ciscoiosMatch15.2\(5\)ea
OR
ciscoiosMatch15.2\(4\)ea4
OR
ciscoiosMatch15.2\(4\)ea2
OR
ciscoiosMatch15.2\(4\)ea5
OR
ciscoiosMatch15.2\(4\)ea6
OR
ciscoiosMatch15.2\(4\)ec1
OR
ciscoiosMatch15.2\(4\)ec2
OR
ciscoiosMatch15.3\(3\)jpi
OR
ciscoiosMatch15.3\(3\)jpj
OR
ciscoiosMatch15.3\(3\)jpr1
OR
ciscocisco_ios_xe_softwareMatch3.2.0se
OR
ciscocisco_ios_xe_softwareMatch3.2.1se
OR
ciscocisco_ios_xe_softwareMatch3.2.2se
OR
ciscocisco_ios_xe_softwareMatch3.2.3se
OR
ciscocisco_ios_xe_softwareMatch3.3.0se
OR
ciscocisco_ios_xe_softwareMatch3.3.1se
OR
ciscocisco_ios_xe_softwareMatch3.3.2se
OR
ciscocisco_ios_xe_softwareMatch3.3.3se
OR
ciscocisco_ios_xe_softwareMatch3.3.4se
OR
ciscocisco_ios_xe_softwareMatch3.3.5se
OR
ciscocisco_ios_xe_softwareMatch3.3.0xo
OR
ciscocisco_ios_xe_softwareMatch3.3.1xo
OR
ciscocisco_ios_xe_softwareMatch3.3.2xo
OR
ciscocisco_ios_xe_softwareMatch3.4.0sg
OR
ciscocisco_ios_xe_softwareMatch3.4.2sg
OR
ciscocisco_ios_xe_softwareMatch3.4.1sg
OR
ciscocisco_ios_xe_softwareMatch3.4.3sg
OR
ciscocisco_ios_xe_softwareMatch3.4.4sg
OR
ciscocisco_ios_xe_softwareMatch3.4.5sg
OR
ciscocisco_ios_xe_softwareMatch3.4.6sg
OR
ciscocisco_ios_xe_softwareMatch3.4.7sg
OR
ciscocisco_ios_xe_softwareMatch3.4.8sg
OR
ciscocisco_ios_xe_softwareMatch3.5.0e
OR
ciscocisco_ios_xe_softwareMatch3.5.1e
OR
ciscocisco_ios_xe_softwareMatch3.5.2e
OR
ciscocisco_ios_xe_softwareMatch3.5.3e
OR
ciscocisco_ios_xe_softwareMatch3.6.0e
OR
ciscocisco_ios_xe_softwareMatch3.6.1e
OR
ciscocisco_ios_xe_softwareMatch3.6.0ae
OR
ciscocisco_ios_xe_softwareMatch3.6.0be
OR
ciscocisco_ios_xe_softwareMatch3.6.2ae
OR
ciscocisco_ios_xe_softwareMatch3.6.3e
OR
ciscocisco_ios_xe_softwareMatch3.6.4e
OR
ciscocisco_ios_xe_softwareMatch3.6.5e
OR
ciscocisco_ios_xe_softwareMatch3.6.6e
OR
ciscocisco_ios_xe_softwareMatch3.6.5ae
OR
ciscocisco_ios_xe_softwareMatch3.6.5be
OR
ciscocisco_ios_xe_softwareMatch3.6.7e
OR
ciscocisco_ios_xe_softwareMatch3.6.7ae
OR
ciscocisco_ios_xe_softwareMatch3.6.7be
OR
ciscocisco_ios_xe_softwareMatch3.7.0e
OR
ciscocisco_ios_xe_softwareMatch3.7.1e
OR
ciscocisco_ios_xe_softwareMatch3.7.2e
OR
ciscocisco_ios_xe_softwareMatch3.7.3e
OR
ciscocisco_ios_xe_softwareMatch3.7.4e
OR
ciscocisco_ios_xe_softwareMatch3.7.5e
OR
ciscocisco_ios_xe_softwareMatch16.1.1
OR
ciscocisco_ios_xe_softwareMatch16.1.2
OR
ciscocisco_ios_xe_softwareMatch16.1.3
OR
ciscocisco_ios_xe_softwareMatch16.2.1
OR
ciscocisco_ios_xe_softwareMatch16.2.2
OR
ciscocisco_ios_xe_softwareMatch3.8.0e
OR
ciscocisco_ios_xe_softwareMatch3.8.1e
OR
ciscocisco_ios_xe_softwareMatch3.8.2e
OR
ciscocisco_ios_xe_softwareMatch3.8.3e
OR
ciscocisco_ios_xe_softwareMatch3.8.4e
OR
ciscocisco_ios_xe_softwareMatch3.8.5e
OR
ciscocisco_ios_xe_softwareMatch3.8.5ae
OR
ciscocisco_ios_xe_softwareMatch16.3.1
OR
ciscocisco_ios_xe_softwareMatch16.3.2
OR
ciscocisco_ios_xe_softwareMatch16.3.3
OR
ciscocisco_ios_xe_softwareMatch16.3.1a
OR
ciscocisco_ios_xe_softwareMatch16.3.4
OR
ciscocisco_ios_xe_softwareMatch16.3.5
OR
ciscocisco_ios_xe_softwareMatch16.3.5b
OR
ciscocisco_ios_xe_softwareMatch16.4.1
OR
ciscocisco_ios_xe_softwareMatch16.5.1
OR
ciscocisco_ios_xe_softwareMatch16.5.1a
OR
ciscocisco_ios_xe_softwareMatch3.9.0e
OR
ciscocisco_ios_xe_softwareMatch3.9.1e
OR
ciscocisco_ios_xe_softwareMatch3.9.2e
OR
ciscocisco_ios_xe_softwareMatch3.9.2be
OR
ciscocisco_ios_xe_softwareMatch16.6.1
OR
ciscocisco_ios_xe_softwareMatch3.10.0e
OR
ciscocisco_ios_xe_softwareMatch3.10.0ce
VendorProductVersionCPE
ciscoios12.2secpe:2.3:o:cisco:ios:12.2se:*:*:*:*:*:*:*
ciscoios12.2excpe:2.3:o:cisco:ios:12.2ex:*:*:*:*:*:*:*
ciscoios12.2eycpe:2.3:o:cisco:ios:12.2ey:*:*:*:*:*:*:*
ciscoios12.2ezcpe:2.3:o:cisco:ios:12.2ez:*:*:*:*:*:*:*
ciscoios15.0eycpe:2.3:o:cisco:ios:15.0ey:*:*:*:*:*:*:*
ciscoios15.0secpe:2.3:o:cisco:ios:15.0se:*:*:*:*:*:*:*
ciscoios15.1sgcpe:2.3:o:cisco:ios:15.1sg:*:*:*:*:*:*:*
ciscoios15.0excpe:2.3:o:cisco:ios:15.0ex:*:*:*:*:*:*:*
ciscoios15.0eacpe:2.3:o:cisco:ios:15.0ea:*:*:*:*:*:*:*
ciscoios15.2ecpe:2.3:o:cisco:ios:15.2e:*:*:*:*:*:*:*
Rows per page:
1-10 of 2621