Lucene search

K
cveCiscoCVE-2018-0257
HistoryApr 19, 2018 - 8:29 p.m.

CVE-2018-0257

2018-04-1920:29:01
CWE-399
cisco
web.nvd.nist.gov
53
cisco
ios xe
cbr series
converged broadband routers
vulnerability
dos
cisco bug ids
nvd
cve-2018-0257

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

39.9%

A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.

Affected configurations

Nvd
Node
ciscoios_xeRange3.183.18.4
OR
ciscoios_xeRange16.616.6.3
OR
ciscoios_xeRange16.716.7.2
OR
ciscoios_xeMatch15.6\(2\)sp
OR
ciscoios_xeMatch16.4
OR
ciscoios_xeMatch16.5
VendorProductVersionCPE
ciscoios_xe*cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
ciscoios_xe15.6(2)spcpe:2.3:o:cisco:ios_xe:15.6\(2\)sp:*:*:*:*:*:*:*
ciscoios_xe16.4cpe:2.3:o:cisco:ios_xe:16.4:*:*:*:*:*:*:*
ciscoios_xe16.5cpe:2.3:o:cisco:ios_xe:16.5:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco cBR Series Converged Broadband Routers",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco cBR Series Converged Broadband Routers"
      }
    ]
  }
]

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

39.9%

Related for CVE-2018-0257