CVE-2018-0418Uncontrolled Resource Consumption in Cisco IOS XR

Severity
8.6HIGHNVD
EPSS
1.0%
top 22.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 13

Description

A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input and validation checking on certain Precision Time Protocol (PTP) ingress traffic to an affected device. An attacker could exploit this vulnerability by injecting malformed traffic into an affected device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-w4jj-rqg4-f8cq: A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an2022-05-13
CVEList
CVE-2018-0418: A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an2018-08-15

📋Vendor Advisories

1
Cisco
Cisco ASR 9000 Series Aggregation Services Routers Precision Time Protocol Denial of Service Vulnerability2018-08-15

💬Community

1
Bugzilla
CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula2018-02-07
CVE-2018-0418 — Uncontrolled Resource Consumption | cvebase