#VU6159 Denial of service in Cisco IOS XE and Cisco IOS - CVE-2017-3850
Published: March 22, 2017 / Updated: March 23, 2017
Vulnerability identifier: #VU6159
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-3850
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco IOS XE
Cisco IOS
Cisco IOS XE
Cisco IOS
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to cause DoS conditions.
The vulnerability exists in Autonomic Networking Infrastructure (ANI) registrar feature due to incomplete input validation . An attacker can send a specially crafted IPv6 packet and cause the affected device to reload.
Successful exploitation of the vulnerability results in denial of service on the vulnerable device.
The vulnerability exists in Autonomic Networking Infrastructure (ANI) registrar feature due to incomplete input validation . An attacker can send a specially crafted IPv6 packet and cause the affected device to reload.
Successful exploitation of the vulnerability results in denial of service on the vulnerable device.
Remediation
Install update from vendor's website.