CVE-2017-3803
published 2017-01-26CVE-2017-3803: A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a…
PriorityP417medium4.7CVSS 3.0
AVAACLPRNUINSCCNINAL
EPSS
0.56%
42.6th percentile
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition. More Information: CSCva72252. Known Affected Releases: 15.2(2)E3 15.2(4)E1. Known Fixed Releases: 15.2(2)E6 15.2(4)E3 15.2(5)E1 15.2(5.3.28i)E1 15.2(6.0.49i)E 3.9(1)E.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_for_catalyst_2960x_and_3750x_switches | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS 15.2(2)E3/15.2(4)E1 Forwarding Queue resource management (CSCva72252 / ID 316067)
vuldb·2026-05-14·CVSS 4.7
CVE-2017-3803 [MEDIUM] Cisco IOS 15.2(2)E3/15.2(4)E1 Forwarding Queue resource management (CSCva72252 / ID 316067)
A vulnerability described as problematic has been identified in Cisco IOS 15.2(2)E3/15.2(4)E1. Affected is an unknown function of the component Forwarding Queue. Such manipulation leads to improper resource management.
This vulnerability is documented as CVE-2017-3803. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-94r3-gpvr-mxj8: A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to caus
ghsa_unreviewed·2022-05-13
CVE-2017-3803 [MEDIUM] CWE-772 GHSA-94r3-gpvr-mxj8: A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to caus
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition. More Information: CSCva72252. Known Affected Releases: 15.2(2)E3 15.2(4)E1. Known Fixed Releases: 15.2(2)E6 15.2(4)E3 15.2(5)E1 15.2(5.3.28i)E1 15.2(6.0.49i)E 3.9(1)E.
Cisco
Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
vendor_cisco·2017-01-18·CVSS 4.7
CVE-2017-3803 [MEDIUM] CWE-399 Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition.
The vulnerability is due to improper processing of IPv6 Neighbor Discovery (ND) packets. An attacker could exploit this vulnerability by sending a number of IPv6 ND packets to be processed by an affected device. An exploit could allow the attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial DoS service condition.
Workarounds that address this vulnerability are available.
This advisory i
Cisco
Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3803 Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
CVE-2017-3803: Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition. The vulnerability is due to improper processing of IPv6 Neighbor Discovery (ND) packets. An attacker could exploit this vulnerability by sending a number of IPv6 ND packets to be processed by an affected device. An exploit could allow the attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial DoS service condition.
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCva72252
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/95632http://www.securitytracker.com/id/1037657https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-catalysthttp://www.securityfocus.com/bid/95632http://www.securitytracker.com/id/1037657https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-catalyst
2017-01-26
Published