← Back

CVE-2018-0241

nvd nist
Published: Apr 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 4.0
Source: NVD

Description

A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IPv4 helper address. An attacker could exploit this vulnerability by sending multiple UDP broadcast packets to the affected device. An exploit could allow the attacker to cause a buffer leak on the affected device, eventually resulting in a DoS condition requiring manual intervention to recover. This vulnerability affects all Cisco IOS XR platforms running 6.3.1, 6.2.3, or earlier releases of Cisco IOS XR Software when at least one IPv4 helper address is configured on an interface of the device. Cisco Bug IDs: CSCvi35625.

Affected (13)

Products: Cisco: Ios Xr
1 product
Ios Xr
Configuration A
13 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 4.0.4.base
Version 4.1.3.base
Version 4.2.4.base
Version 4.3.4.base
Version 4.4.3.ce
Version 5.0.3.ce
Version 5.1.4.base
Version 5.2.5.ce
Version 5.3.4.base
Version 5.4.3.ce
Version 6.0.4.base
Version 6.1.4.base
Version 6.2.3.base
Running on/withPlatform Versions
Cisco
Asr 9001
All versions
Cisco
Asr 9006
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9906
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions

Related CWEs

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.