cbcvebase.
CVE-2018-0257
published 2018-04-19

CVE-2018-0257: A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause…

PriorityP419medium4.3CVSS 3.0
AVAACLPRNUINSUCNINAL
EPSS
0.80%
53.0th percentile
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscocbr_series_converged_broadband_routers_high_cpu_usage
ciscoios_xe<= 16.7.2
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe16.6 – 16.6.3
ciscoios_xe3.18 – 3.18.4

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.