Lucene search

K
cveCiscoCVE-2017-3856
HistoryMar 22, 2017 - 7:59 p.m.

CVE-2017-3856

2017-03-2219:59:00
CWE-400
CWE-399
cisco
web.nvd.nist.gov
52
4
cve-2017-3856
cisco
vulnerability
web user interface
ios xe
denial of service
nvd
remote attacker
dos

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

72.1%

A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the web user interface of the software is enabled. By default, the web user interface is not enabled. Cisco Bug IDs: CSCup70353.

Affected configurations

Nvd
Node
ciscoios_xeMatch3.1.0s
OR
ciscoios_xeMatch3.1.0sg
OR
ciscoios_xeMatch3.1.1s
OR
ciscoios_xeMatch3.1.1sg
OR
ciscoios_xeMatch3.1.2s
OR
ciscoios_xeMatch3.1.3as
OR
ciscoios_xeMatch3.1.3s
OR
ciscoios_xeMatch3.1.4as
OR
ciscoios_xeMatch3.1.4s
OR
ciscoios_xeMatch3.1s
OR
ciscoios_xeMatch3.1sg
OR
ciscoios_xeMatch3.2.0ja
OR
ciscoios_xeMatch3.2.0se
OR
ciscoios_xeMatch3.2.0sg
OR
ciscoios_xeMatch3.2.0xo
OR
ciscoios_xeMatch3.2.1s
OR
ciscoios_xeMatch3.2.1se
OR
ciscoios_xeMatch3.2.1sg
OR
ciscoios_xeMatch3.2.1xo
OR
ciscoios_xeMatch3.2.2s
OR
ciscoios_xeMatch3.2.2se
OR
ciscoios_xeMatch3.2.2sg
OR
ciscoios_xeMatch3.2.3se
OR
ciscoios_xeMatch3.2.3sg
OR
ciscoios_xeMatch3.2.4sg
OR
ciscoios_xeMatch3.2.5sg
OR
ciscoios_xeMatch3.2.6sg
OR
ciscoios_xeMatch3.2.7sg
OR
ciscoios_xeMatch3.2.8sg
OR
ciscoios_xeMatch3.2.9sg
OR
ciscoios_xeMatch3.2.11sg
OR
ciscoios_xeMatch3.2ja
OR
ciscoios_xeMatch3.2s
OR
ciscoios_xeMatch3.2se
OR
ciscoios_xeMatch3.2sg
OR
ciscoios_xeMatch3.2xo
OR
ciscoios_xeMatch3.3.0s
OR
ciscoios_xeMatch3.3.0se
OR
ciscoios_xeMatch3.3.0sg
OR
ciscoios_xeMatch3.3.0sq
OR
ciscoios_xeMatch3.3.0xo
OR
ciscoios_xeMatch3.3.1s
OR
ciscoios_xeMatch3.3.1se
OR
ciscoios_xeMatch3.3.1sg
OR
ciscoios_xeMatch3.3.1sq
OR
ciscoios_xeMatch3.3.1xo
OR
ciscoios_xeMatch3.3.2s
OR
ciscoios_xeMatch3.3.2se
OR
ciscoios_xeMatch3.3.2sg
OR
ciscoios_xeMatch3.3.2xo
OR
ciscoios_xeMatch3.3.3se
OR
ciscoios_xeMatch3.3.4se
OR
ciscoios_xeMatch3.3.5se
OR
ciscoios_xeMatch3.3s
OR
ciscoios_xeMatch3.3se
OR
ciscoios_xeMatch3.3sg
OR
ciscoios_xeMatch3.3sq
OR
ciscoios_xeMatch3.3xo
OR
ciscoios_xeMatch3.4.0as
OR
ciscoios_xeMatch3.4.0s
OR
ciscoios_xeMatch3.4.0sg
OR
ciscoios_xeMatch3.4.0sq
OR
ciscoios_xeMatch3.4.1s
OR
ciscoios_xeMatch3.4.1sg
OR
ciscoios_xeMatch3.4.1sq
OR
ciscoios_xeMatch3.4.2s
OR
ciscoios_xeMatch3.4.2sg
OR
ciscoios_xeMatch3.4.3s
OR
ciscoios_xeMatch3.4.3sg
OR
ciscoios_xeMatch3.4.4s
OR
ciscoios_xeMatch3.4.4sg
OR
ciscoios_xeMatch3.4.5s
OR
ciscoios_xeMatch3.4.5sg
OR
ciscoios_xeMatch3.4.6s
OR
ciscoios_xeMatch3.4.6sg
OR
ciscoios_xeMatch3.4.7sg
OR
ciscoios_xeMatch3.4.8sg
OR
ciscoios_xeMatch3.4s
OR
ciscoios_xeMatch3.4sg
OR
ciscoios_xeMatch3.4sq
OR
ciscoios_xeMatch3.5.0e
OR
ciscoios_xeMatch3.5.0s
OR
ciscoios_xeMatch3.5.0sq
OR
ciscoios_xeMatch3.5.1e
OR
ciscoios_xeMatch3.5.1s
OR
ciscoios_xeMatch3.5.1sq
OR
ciscoios_xeMatch3.5.2e
OR
ciscoios_xeMatch3.5.2s
OR
ciscoios_xeMatch3.5.2sq
OR
ciscoios_xeMatch3.5.3e
OR
ciscoios_xeMatch3.5.3sq
OR
ciscoios_xeMatch3.5.4sq
OR
ciscoios_xeMatch3.5.5sq
OR
ciscoios_xeMatch3.5e
OR
ciscoios_xeMatch3.5s
OR
ciscoios_xeMatch3.5sq
OR
ciscoios_xeMatch3.6.0e
OR
ciscoios_xeMatch3.6.0s
OR
ciscoios_xeMatch3.6.1e
OR
ciscoios_xeMatch3.6.1s
OR
ciscoios_xeMatch3.6.2ae
OR
ciscoios_xeMatch3.6.2s
OR
ciscoios_xeMatch3.6.3e
OR
ciscoios_xeMatch3.6.4e
OR
ciscoios_xeMatch3.6.5ae
OR
ciscoios_xeMatch3.6.5be
OR
ciscoios_xeMatch3.6.5e
OR
ciscoios_xeMatch3.6e
OR
ciscoios_xeMatch3.6s
OR
ciscoios_xeMatch3.7.0bs
OR
ciscoios_xeMatch3.7.0e
OR
ciscoios_xeMatch3.7.0s
OR
ciscoios_xeMatch3.7.1e
OR
ciscoios_xeMatch3.7.1s
OR
ciscoios_xeMatch3.7.2e
OR
ciscoios_xeMatch3.7.2s
OR
ciscoios_xeMatch3.7.2ts
OR
ciscoios_xeMatch3.7.3e
OR
ciscoios_xeMatch3.7.3s
OR
ciscoios_xeMatch3.7.4e
OR
ciscoios_xeMatch3.7.4s
OR
ciscoios_xeMatch3.7.5s
OR
ciscoios_xeMatch3.7.6s
OR
ciscoios_xeMatch3.7.7s
OR
ciscoios_xeMatch3.7e
OR
ciscoios_xeMatch3.7s
OR
ciscoios_xeMatch3.8.0e
OR
ciscoios_xeMatch3.8.0ex
OR
ciscoios_xeMatch3.8.0s
OR
ciscoios_xeMatch3.8.1e
OR
ciscoios_xeMatch3.8.1s
OR
ciscoios_xeMatch3.8.2e
OR
ciscoios_xeMatch3.8.2s
OR
ciscoios_xeMatch3.8e
OR
ciscoios_xeMatch3.8ex
OR
ciscoios_xeMatch3.8s
OR
ciscoios_xeMatch3.9.0e
OR
ciscoios_xeMatch3.9.0s
OR
ciscoios_xeMatch3.9.1s
OR
ciscoios_xeMatch3.9.2s
OR
ciscoios_xeMatch3.9e
OR
ciscoios_xeMatch3.9s
OR
ciscoios_xeMatch3.10.0s
OR
ciscoios_xeMatch3.10.1s
OR
ciscoios_xeMatch3.10.1xbs
OR
ciscoios_xeMatch3.10.2s
OR
ciscoios_xeMatch3.10.2ts
OR
ciscoios_xeMatch3.10.3s
OR
ciscoios_xeMatch3.10.4s
OR
ciscoios_xeMatch3.10.5s
OR
ciscoios_xeMatch3.10.6s
OR
ciscoios_xeMatch3.10.7s
OR
ciscoios_xeMatch3.10.8s
OR
ciscoios_xeMatch3.10s
OR
ciscoios_xeMatch3.11.0s
OR
ciscoios_xeMatch3.11.1s
OR
ciscoios_xeMatch3.11.2s
OR
ciscoios_xeMatch3.11.3s
OR
ciscoios_xeMatch3.11.4s
OR
ciscoios_xeMatch3.11s
OR
ciscoios_xeMatch3.12.0as
OR
ciscoios_xeMatch3.12.0s
OR
ciscoios_xeMatch3.12.1s
OR
ciscoios_xeMatch3.12.2s
OR
ciscoios_xeMatch3.12.3s
OR
ciscoios_xeMatch3.12.4s
OR
ciscoios_xeMatch3.12s
OR
ciscoios_xeMatch3.13.0as
OR
ciscoios_xeMatch3.13.0s
OR
ciscoios_xeMatch3.13.1s
OR
ciscoios_xeMatch3.13.2as
OR
ciscoios_xeMatch3.13.2s
OR
ciscoios_xeMatch3.13.3s
OR
ciscoios_xeMatch3.13.4s
OR
ciscoios_xeMatch3.13s
OR
ciscoios_xeMatch3.14.0s
OR
ciscoios_xeMatch3.14.1s
OR
ciscoios_xeMatch3.14.2s
OR
ciscoios_xeMatch3.14.3s
OR
ciscoios_xeMatch3.14.4s
OR
ciscoios_xeMatch3.14s
OR
ciscoios_xeMatch3.15.0s
OR
ciscoios_xeMatch3.15.1cs
OR
ciscoios_xeMatch3.15.1s
OR
ciscoios_xeMatch3.15.2s
OR
ciscoios_xeMatch3.15.3s
OR
ciscoios_xeMatch3.15s
OR
ciscoios_xeMatch3.16.0cs
OR
ciscoios_xeMatch3.16.0s
OR
ciscoios_xeMatch3.16.1as
OR
ciscoios_xeMatch3.16.1s
OR
ciscoios_xeMatch3.16s
OR
ciscoios_xeMatch3.17.0s
OR
ciscoios_xeMatch3.17.1as
OR
ciscoios_xeMatch3.17.1s
OR
ciscoios_xeMatch3.17.2s
OR
ciscoios_xeMatch3.17.3s
OR
ciscoios_xeMatch3.17s
VendorProductVersionCPE
ciscoios_xe3.1.0scpe:2.3:o:cisco:ios_xe:3.1.0s:*:*:*:*:*:*:*
ciscoios_xe3.1.0sgcpe:2.3:o:cisco:ios_xe:3.1.0sg:*:*:*:*:*:*:*
ciscoios_xe3.1.1scpe:2.3:o:cisco:ios_xe:3.1.1s:*:*:*:*:*:*:*
ciscoios_xe3.1.1sgcpe:2.3:o:cisco:ios_xe:3.1.1sg:*:*:*:*:*:*:*
ciscoios_xe3.1.2scpe:2.3:o:cisco:ios_xe:3.1.2s:*:*:*:*:*:*:*
ciscoios_xe3.1.3ascpe:2.3:o:cisco:ios_xe:3.1.3as:*:*:*:*:*:*:*
ciscoios_xe3.1.3scpe:2.3:o:cisco:ios_xe:3.1.3s:*:*:*:*:*:*:*
ciscoios_xe3.1.4ascpe:2.3:o:cisco:ios_xe:3.1.4as:*:*:*:*:*:*:*
ciscoios_xe3.1.4scpe:2.3:o:cisco:ios_xe:3.1.4s:*:*:*:*:*:*:*
ciscoios_xe3.1scpe:2.3:o:cisco:ios_xe:3.1s:*:*:*:*:*:*:*
Rows per page:
1-10 of 1981

CNA Affected

[
  {
    "product": "Cisco IOS XE",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco IOS XE"
      }
    ]
  }
]

Social References

More

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

72.1%