← Back

CVE-2018-0209

nvd nist
Published: Mar 8, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.1 / Impact: 4.0
Source: NVD

Description

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.

Affected (2)

1 product
Configuration A
2 vulnerable · 19 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 2.2.5.68
Version 2.3.0.130
Running on/withPlatform Versions
Cisco
Sf500 24
All versions
Cisco
Sf500 24mp
All versions
Cisco
Sf500 24p
All versions
Cisco
Sf500 48
All versions
Cisco
Sf500 48mp
All versions
Cisco
Sf500 48p
All versions
Cisco
Sg500 28
All versions
Cisco
Sg500 28mpp
All versions
Cisco
Sg500 28p
All versions
Cisco
Sg500 52
All versions
Cisco
Sg500 52mp
All versions
Cisco
Sg500 52p
All versions
Cisco
Sg500x 24
All versions
Cisco
Sg500x 24mpp
All versions
Cisco
Sg500x 24p
All versions
Cisco
Sg500x 48
All versions
Cisco
Sg500x 48mp
All versions
Cisco
Sg500x 48p
All versions
Cisco
Sg500xg 8f8t
All versions

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.