Denial of service in Cisco IOS XE and Cisco IOS - CVE-2017-3850

 

Denial of service in Cisco IOS XE and Cisco IOS - CVE-2017-3850

Published: March 22, 2017 / Updated: March 23, 2017


Vulnerability identifier: #VU6159
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3850
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS conditions.

The vulnerability exists in Autonomic Networking Infrastructure (ANI) registrar feature due to incomplete input validation . An attacker can send a specially crafted IPv6 packet and cause the affected device to reload.

Successful exploitation of the vulnerability results in denial of service on the vulnerable device.

Affected software

Cisco IOS XE
Cisco IOS

How to mitigate CVE-2017-3850

Install update from vendor's website.


External References

Related Security Bulletins