← Back

CVE-2019-1740

nvd nist
Published: Mar 28, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

Affected (149)

Products: Cisco: Ios Xe, Ios
2 products
Ios Xe
Ios
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.2.1
Version 16.2.2
Version 16.3.1
Version 16.3.1a
Version 16.3.2
Version 16.3.3
Version 16.3.4
Version 16.4.1
Version 16.4.2
Version 16.4.3
Version 16.5.1
Version 16.5.1a
Version 16.5.1b
Version 16.9.3s
Version 16.9.4c
Version 3.16.0as
Version 3.16.0bs
Version 3.16.0cs
Version 3.16.0s
Version 3.16.1as
Version 3.16.1s
Version 3.16.2as
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.2s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0as
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2asp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3s
Version 3.18.4s
Version 3.2.0ja
Configuration B
91 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 15.3(3)jd11
Version 15.3(3)jd12
Version 15.3(3)jd13
Version 15.3(3)jd14
Version 15.3(3)jd2
Version 15.3(3)jd3
Version 15.3(3)jd4
Version 15.3(3)jd5
Version 15.3(3)jd6
Version 15.3(3)jd7
Version 15.3(3)jd8
Version 15.3(3)jd9
Version 15.3(3)jd
Version 15.3(3)je
Version 15.3(3)jf1
Version 15.3(3)jf2
Version 15.3(3)jf4
Version 15.3(3)jf5
Version 15.3(3)jf
Version 15.3(3)jg1
Version 15.3(3)jg
Version 15.3(3)jh
Version 15.3(3)jk6
Version 15.3(3)jnp1
Version 15.3(3)jnp3
Version 15.3(3)jnp
Version 15.3(3)jpb1
Version 15.3(3)jpb
Version 15.3(3)jpc1
Version 15.3(3)jpc2
Version 15.3(3)jpc3
Version 15.3(3)jpc5
Version 15.3(3)jpc
Version 15.3(3)jpd
Version 15.5(3)m0a
Version 15.5(3)m1
Version 15.5(3)m2
Version 15.5(3)m2a
Version 15.5(3)m3
Version 15.5(3)m4
Version 15.5(3)m4a
Version 15.5(3)m4b
Version 15.5(3)m4c
Version 15.5(3)m5
Version 15.5(3)m
Version 15.5(3)s0a
Version 15.5(3)s1
Version 15.5(3)s1a
Version 15.5(3)s2
Version 15.5(3)s3
Version 15.5(3)s4
Version 15.5(3)s5
Version 15.5(3)s
Version 15.5(3)sn0a
Version 15.5(3)sn
Version 15.6(1)s1
Version 15.6(1)s2
Version 15.6(1)s3
Version 15.6(1)s4
Version 15.6(1)s
Version 15.6(1)sn1
Version 15.6(1)sn2
Version 15.6(1)sn3
Version 15.6(1)sn
Version 15.6(1)t0a
Version 15.6(1)t1
Version 15.6(1)t2
Version 15.6(1)t
Version 15.6(2)s1
Version 15.6(2)s2
Version 15.6(2)s3
Version 15.6(2)s4
Version 15.6(2)s
Version 15.6(2)sn
Version 15.6(2)t0a
Version 15.6(2)t1
Version 15.6(2)t2
Version 15.6(2)t
Version 15.6(3)m0a
Version 15.6(3)m1
Version 15.6(3)m1a
Version 15.6(3)m1b
Version 15.6(3)m
Version 15.6(3)sn
Version 15.6(4)sn
Version 15.6(5)sn
Version 15.6(6)sn
Version 15.6(7)sn1
Version 15.6(7)sn2
Version 15.6(7)sn3
Version 15.6(7)sn

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.