Resource management errors in Cisco IOS XE - CVE-2018-0189
Published: March 30, 2018
Vulnerability identifier: #VU11373
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0189
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the Forwarding Information Base (FIB) code due to a limitation in the way the FIB is internally representing recursive routes. A remote attacker can inject routes into the routing protocol that have a specific recursive pattern and cause the service to crash.
The weakness exists in the Forwarding Information Base (FIB) code due to a limitation in the way the FIB is internally representing recursive routes. A remote attacker can inject routes into the routing protocol that have a specific recursive pattern and cause the service to crash.
Affected software
Cisco IOS XE
How to mitigate CVE-2018-0189
Update to versions 15.6(2)SP1, 15.5(3)S5, 15.4(3)S7, 16.4.2, 16.4.1, 16.3.3, 11.3.3, 16.5(0.13), 16.4.2, 16.4.1, 16.4(0.187), 16.3.3, 16.3(1.81), 15.7(3.1.8A)OT, 15.7(3.1.4A)OT, 15.7(0.2)M, 15.6(3)M1, 15.6(3.0p)M, 15.6(2)T2, 15.6(1)S4.2, 15.6(1)S2.18, 15.6(1.17)S0.47, 15.6(1.9)SP1, 15.5(4)IA1.1, 15.5(3)S4.1, 15.5(3)M5, 15.5(3)M4.1, 15.5(0)IA101.142, 15.4(3)S6.2, 15.4(3)S6.1, 15.4(3)M7, 15.4(1)SY2, 15.4(1)IA1.201, 15.2(6.3.0i)E, 15.2(5)EX, 15.2(5)E2, 15.2(5)E1, 15.2(5.8.1)EA, 15.2(5.7.2)EA, 15.2(5.6.56)EA, 15.2(5.4.1i)E2, 15.2(5.3.29i)E1, 15.2(5.3.27i)E1, 15.2(4)EA6, 15.2(4)E5, 15.2(4.6.22)EA5, 15.2(1)SY6, 15.2(1)SY5.105 or 11.3(3).