← Back

CVE-2017-3856

nvd nist
Published: Mar 22, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the web user interface of the software is enabled. By default, the web user interface is not enabled. Cisco Bug IDs: CSCup70353.

Affected (198)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
198 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 3.1.0s
Version 3.1.0sg
Version 3.1.1s
Version 3.1.1sg
Version 3.1.2s
Version 3.1.3as
Version 3.1.3s
Version 3.1.4as
Version 3.1.4s
Version 3.10.0s
Version 3.10.1s
Version 3.10.1xbs
Version 3.10.2s
Version 3.10.2ts
Version 3.10.3s
Version 3.10.4s
Version 3.10.5s
Version 3.10.6s
Version 3.10.7s
Version 3.10.8s
Version 3.10s
Version 3.11.0s
Version 3.11.1s
Version 3.11.2s
Version 3.11.3s
Version 3.11.4s
Version 3.11s
Version 3.12.0as
Version 3.12.0s
Version 3.12.1s
Version 3.12.2s
Version 3.12.3s
Version 3.12.4s
Version 3.12s
Version 3.13.0as
Version 3.13.0s
Version 3.13.1s
Version 3.13.2as
Version 3.13.2s
Version 3.13.3s
Version 3.13.4s
Version 3.13s
Version 3.14.0s
Version 3.14.1s
Version 3.14.2s
Version 3.14.3s
Version 3.14.4s
Version 3.14s
Version 3.15.0s
Version 3.15.1cs
Version 3.15.1s
Version 3.15.2s
Version 3.15.3s
Version 3.15s
Version 3.16.0cs
Version 3.16.0s
Version 3.16.1as
Version 3.16.1s
Version 3.16s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.2s
Version 3.17.3s
Version 3.17s
Version 3.1s
Version 3.1sg
Version 3.2.0ja
Version 3.2.0se
Version 3.2.0sg
Version 3.2.0xo
Version 3.2.11sg
Version 3.2.1s
Version 3.2.1se
Version 3.2.1sg
Version 3.2.1xo
Version 3.2.2s
Version 3.2.2se
Version 3.2.2sg
Version 3.2.3se
Version 3.2.3sg
Version 3.2.4sg
Version 3.2.5sg
Version 3.2.6sg
Version 3.2.7sg
Version 3.2.8sg
Version 3.2.9sg
Version 3.2ja
Version 3.2s
Version 3.2se
Version 3.2sg
Version 3.2xo
Version 3.3.0s
Version 3.3.0se
Version 3.3.0sg
Version 3.3.0sq
Version 3.3.0xo
Version 3.3.1s
Version 3.3.1se
Version 3.3.1sg
Version 3.3.1sq
Version 3.3.1xo
Version 3.3.2s
Version 3.3.2se
Version 3.3.2sg
Version 3.3.2xo
Version 3.3.3se
Version 3.3.4se
Version 3.3.5se
Version 3.3s
Version 3.3se
Version 3.3sg
Version 3.3sq
Version 3.3xo
Version 3.4.0as
Version 3.4.0s
Version 3.4.0sg
Version 3.4.0sq
Version 3.4.1s
Version 3.4.1sg
Version 3.4.1sq
Version 3.4.2s
Version 3.4.2sg
Version 3.4.3s
Version 3.4.3sg
Version 3.4.4s
Version 3.4.4sg
Version 3.4.5s
Version 3.4.5sg
Version 3.4.6s
Version 3.4.6sg
Version 3.4.7sg
Version 3.4.8sg
Version 3.4s
Version 3.4sg
Version 3.4sq
Version 3.5.0e
Version 3.5.0s
Version 3.5.0sq
Version 3.5.1e
Version 3.5.1s
Version 3.5.1sq
Version 3.5.2e
Version 3.5.2s
Version 3.5.2sq
Version 3.5.3e
Version 3.5.3sq
Version 3.5.4sq
Version 3.5.5sq
Version 3.5e
Version 3.5s
Version 3.5sq
Version 3.6.0e
Version 3.6.0s
Version 3.6.1e
Version 3.6.1s
Version 3.6.2ae
Version 3.6.2s
Version 3.6.3e
Version 3.6.4e
Version 3.6.5ae
Version 3.6.5be
Version 3.6.5e
Version 3.6e
Version 3.6s
Version 3.7.0bs
Version 3.7.0e
Version 3.7.0s
Version 3.7.1e
Version 3.7.1s
Version 3.7.2e
Version 3.7.2s
Version 3.7.2ts
Version 3.7.3e
Version 3.7.3s
Version 3.7.4e
Version 3.7.4s
Version 3.7.5s
Version 3.7.6s
Version 3.7.7s
Version 3.7e
Version 3.7s
Version 3.8.0e
Version 3.8.0ex
Version 3.8.0s
Version 3.8.1e
Version 3.8.1s
Version 3.8.2e
Version 3.8.2s
Version 3.8e
Version 3.8ex
Version 3.8s
Version 3.9.0e
Version 3.9.0s
Version 3.9.1s
Version 3.9.2s
Version 3.9e
Version 3.9s

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.