Lucene search

K
cveCiscoCVE-2017-3824
HistoryFeb 03, 2017 - 7:59 a.m.

CVE-2017-3824

2017-02-0307:59:00
CWE-119
cisco
web.nvd.nist.gov
31
cisco
cbr
vulnerability
cve-2017-3824
dos
nvd
cisco ios xe
cscux40637
list headers
denial of service

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.004

Percentile

72.2%

A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Routers running vulnerable versions of Cisco IOS XE are affected. More Information: CSCux40637. Known Affected Releases: 15.5(3)S 15.6(1)S. Known Fixed Releases: 15.5(3)S2 15.6(1)S1 15.6(2)S 15.6(2)SP 16.4(1).

Affected configurations

Nvd
Node
ciscoios_xeMatch3.16.0
OR
ciscoios_xeMatch3.16.1
OR
ciscoios_xeMatch3.17.0
AND
ciscocbr-8_converged_broadband_routerMatch-
VendorProductVersionCPE
ciscoios_xe3.16.0cpe:2.3:o:cisco:ios_xe:3.16.0:*:*:*:*:*:*:*
ciscoios_xe3.16.1cpe:2.3:o:cisco:ios_xe:3.16.1:*:*:*:*:*:*:*
ciscoios_xe3.17.0cpe:2.3:o:cisco:ios_xe:3.17.0:*:*:*:*:*:*:*
ciscocbr-8_converged_broadband_router-cpe:2.3:h:cisco:cbr-8_converged_broadband_router:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco IOS XE 15.x",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco IOS XE 15.x"
      }
    ]
  }
]

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.004

Percentile

72.2%

Related for CVE-2017-3824