CVE-2018-0257
published 2018-04-19CVE-2018-0257: A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause…
PriorityP419medium4.3CVSS 3.0
AVAACLPRNUINSUCNINAL
EPSS
0.80%
53.0th percentile
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cbr_series_converged_broadband_routers_high_cpu_usage | — | — |
| cisco | ios_xe | <= 16.7.2 | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | 16.6 – 16.6.3 | — |
| cisco | ios_xe | 3.18 – 3.18.4 | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
vendor_cisco·2018-04-18·CVSS 4.3
CVE-2018-0257 [MEDIUM] CWE-399 Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/secu
Cisco
Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0257 Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
CVE-2018-0257: Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCvg73687
GHSA
GHSA-pgx5-6r92-gp92: A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to
ghsa_unreviewed·2022-05-13
CVE-2018-0257 [MEDIUM] GHSA-pgx5-6r92-gp92: A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vulnerability by sending certain DHCP packets to a specific segment of an affected device. A successful exploit could allow the attacker to increase CPU usage on the affected device and cause a DoS condition. Cisco Bug IDs: CSCvg73687.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103948http://www.securitytracker.com/id/1040716https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-cbr8http://www.securityfocus.com/bid/103948http://www.securitytracker.com/id/1040716https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-cbr8
2018-04-19
Published