#VU16927 Improper input validation in Cisco IOS/IOS XE - CVE-2018-0282
Published: January 9, 2019 / Updated: January 10, 2019
Cisco IOS/IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists in the TCP socket code due to a state condition between the socket state and the transmission control block (TCB) state. A remote attacker can send specific HTTP requests at a sustained rate to a reachable IP address of the affected software and cause the affected device to reload, resulting in a denial of service (DoS) condition on an affected device.