#VU11362 Improper input validation in Cisco IOS XE - CVE-2018-0173

 

#VU11362 Improper input validation in Cisco IOS XE - CVE-2018-0173

Published: March 30, 2018 / Updated: March 8, 2022


Vulnerability identifier: #VU11362
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2018-0173
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets due to incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. A remote attacker can send a specially crafted DHCPv4 packet and cause the service to crash.

Remediation

Update to evrsions 16.6(2.67), 16.5(1.321), 16.3(5.73), 15.6(2.18)SP3, 15.6(2)SP4, 15.5(3)S6.23, 15.4(3)S9, 15.2(6.5.1i)E1, 15.2(6.4.66i)E1, 15.2(6.4.63i)E1, 15.2(6)E1, 15.2(4.7.6)EA7, 15.0(1.9.1)SQD8 or 12.2(60)EZ13.

External links