CVE-2017-3824
published 2017-02-03CVE-2017-3824: A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the…
PriorityP434medium6.8CVSS 3.0
AVNACHPRNUINSCCNINAH
EPSS
2.08%
79.5th percentile
A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Routers running vulnerable versions of Cisco IOS XE are affected. More Information: CSCux40637. Known Affected Releases: 15.5(3)S 15.6(1)S. Known Fixed Releases: 15.5(3)S2 15.6(1)S1 15.6(2)S 15.6(2)SP 16.4(1).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cbr_series_converged_broadband_routers_list_headers | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9rq-2938-mw9p: A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cau
ghsa_unreviewed·2022-05-17
CVE-2017-3824 [MEDIUM] CWE-119 GHSA-m9rq-2938-mw9p: A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cau
A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Routers running vulnerable versions of Cisco IOS XE are affected. More Information: CSCux40637. Known Affected Releases: 15.5(3)S 15.6(1)S. Known Fixed Releases: 15.5(3)S2 15.6(1)S1 15.6(2)S 15.6(2)SP 16.4(1).
Cisco
Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
vendor_cisco·2017-02-01·CVSS 6.8
CVE-2017-3824 [MEDIUM] CWE-119 Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to memory corruption. An attacker could exploit this vulnerability by sending crafted PacketCable Multimedia (PCMM) packets to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-cbr
Cisco
Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3824 Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
CVE-2017-3824: Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability
A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to memory corruption. An attacker could exploit this vulnerability by sending crafted PacketCable Multimedia (PCMM) packets to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. There are no
CVSS: 3.0
CWE: CWE-119, CWE-119
Bug IDs: CSCux40637
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/95937http://www.securitytracker.com/id/1037774https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-cbrhttp://www.securityfocus.com/bid/95937http://www.securitytracker.com/id/1037774https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-cbr
2017-02-03
Published