CVE-2018-0470
published 2018-10-05CVE-2018-0470: A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an…
PriorityP350high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
EPSS
4.40%
90.3th percentile
A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the affected software improperly parsing malformed HTTP packets that are destined to a device. An attacker could exploit this vulnerability by sending a malformed HTTP packet to an affected device for processing. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected device, resulting in a DoS condition.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m395-rxf5-2vf4: A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on
ghsa_unreviewed·2022-05-13
CVE-2018-0470 [HIGH] CWE-119 GHSA-m395-rxf5-2vf4: A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on
A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the affected software improperly parsing malformed HTTP packets that are destined to a device. An attacker could exploit this vulnerability by sending a malformed HTTP packet to an affected device for processing. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected device, resulting in a DoS condition.
CISA ICS
Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700
cisa_ics·2019-04-05·CVSS 6.5
[MEDIUM] Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700
Last RevisedApril 05, 2019
Alert CodeICSA-19-094-03
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Stratix 5400/5410/5700/8000/8300, ArmorStratix 5700
- Vulnerabilities: Resource Management Errors, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition or time synchronization issues across the network via reloading the
Cisco
Cisco IOS XE Software HTTP Denial of Service Vulnerability
vendor_cisco·2018-09-26·CVSS 8.6
CVE-2018-0470 [HIGH] CWE-399 Cisco IOS XE Software HTTP Denial of Service Vulnerability
Cisco IOS XE Software HTTP Denial of Service Vulnerability
A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to the affected software improperly parsing malformed HTTP packets that are destined to a device. An attacker could exploit this vulnerability by sending a malformed HTTP packet to an affected device for processing. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected device, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory
Cisco
Cisco IOS XE Software HTTP Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0470 Cisco IOS XE Software HTTP Denial of Service Vulnerability
CVE-2018-0470: Cisco IOS XE Software HTTP Denial of Service Vulnerability
A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the affected software improperly parsing malformed HTTP packets that are destined to a device. An attacker could exploit this vulnerability by sending a malformed HTTP packet to an affected device for processing. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected device, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCvb
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105397http://www.securitytracker.com/id/1041737https://ics-cert.us-cert.gov/advisories/ICSA-19-094-03https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-webdoshttp://www.securityfocus.com/bid/105397http://www.securitytracker.com/id/1041737https://ics-cert.us-cert.gov/advisories/ICSA-19-094-03https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-webdos
2018-10-05
Published