#VU6159 Denial of service in Cisco IOS XE and Cisco IOS - CVE-2017-3850

 

#VU6159 Denial of service in Cisco IOS XE and Cisco IOS - CVE-2017-3850

Published: March 22, 2017 / Updated: March 23, 2017


Vulnerability identifier: #VU6159
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-3850
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XE
Cisco IOS
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to cause DoS conditions.

The vulnerability exists in Autonomic Networking Infrastructure (ANI) registrar feature due to incomplete input validation . An attacker can send a specially crafted IPv6 packet and cause the affected device to reload.

Successful exploitation of the vulnerability results in denial of service on the vulnerable device.

Remediation

Install update from vendor's website.

External links