CVE-2018-0170Use After Free in Cisco IOS XE

CWE-416Use After Free4 documents4 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMay 13

Description

A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been freed. An attacker could exploit this vulnerability by sending crafted, malformed IP packets to an affected device. A successfu

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDcisco/ios_xe16.4.1

🔴Vulnerability Details

2
GHSA
GHSA-h5j7-h5xp-7395: A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial o2022-05-13
CVEList
CVE-2018-0170: A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial o2018-03-28

📋Vendor Advisories

1
Cisco
Cisco IOS XE Software with Cisco Umbrella Integration Denial of Service Vulnerability2018-03-28
CVE-2018-0170 — Use After Free in Cisco IOS XE | cvebase