Improper input validation in Cisco 550X Series Stackable Managed Switches - CVE-2018-0209

 

Improper input validation in Cisco 550X Series Stackable Managed Switches - CVE-2018-0209

Published: March 12, 2018


Vulnerability identifier: #VU10937
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0209
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The weakness exists in the Simple Network Management Protocol (SNMP) subsystem communication channel due to lack of proper input throttling of ingress SNMP traffic over an internal interface. A remote attacker can send a specially crafted heavy stream of SNMP traffic and cause the device to reload.

Affected software

Cisco 550X Series Stackable Managed Switches

How to mitigate CVE-2018-0209

Install update from vendor's website.


External References

Related Security Bulletins