#VU11350 Use after free in Cisco IOS XE - CVE-2018-0170

 

#VU11350 Use after free in Cisco IOS XE - CVE-2018-0170

Published: March 30, 2018


Vulnerability identifier: #VU11350
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-0170
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the Cisco Umbrella Integration feature due to logic error when handling a malformed incoming packet, leading to access to an internal data structure after it has been freed. A remote attacker can send specially crafted, malformed IP packets, trigger use after free and cause the service to crash.

Remediation

Update to versions 16.5(0.93), 16.4.1, 16.4(0.228), 16.3.3, 16.3(1.80) or 11.3(3).

External links