CVE-2018-0471
published 2018-10-05CVE-2018-0471: A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent…
PriorityP433high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.85%
54.0th percentile
A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain CDP packets. An attacker could exploit this vulnerability by sending certain CDP packets to an affected device. A successful exploit could cause an affected device to continuously consume memory and eventually result in a memory allocation failure that leads to a crash, triggering a reload of the affected device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
vendor_cisco·2018-09-26·CVSS 7.4
CVE-2018-0471 [HIGH] CWE-400 Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
A vulnerability in the Cisco Discovery Protocol (CDP) module of
Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent
attacker to cause a memory leak that may lead to a denial of service
(DoS) condition.
The vulnerability is due to incorrect processing
of certain CDP packets. An attacker could exploit this vulnerability by
sending certain CDP packets to an affected device. A successful exploit
could cause an affected device to continuously consume memory and
eventually result in a memory allocation failure that leads to a crash,
triggering a reload of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address thi
Cisco
Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0471 Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
CVE-2018-0471: Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain CDP packets. An attacker could exploit this vulnerability by sending certain CDP packets to an affected device. A successful exploit could cause an affected device to continuously consume memory and eventually result in a memory allocation failure that leads to a crash, triggering a reload of the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE:
GHSA
GHSA-5234-wvr8-wqqh: A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16
ghsa_unreviewed·2022-05-13
CVE-2018-0471 [HIGH] CWE-772 GHSA-5234-wvr8-wqqh: A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16
A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain CDP packets. An attacker could exploit this vulnerability by sending certain CDP packets to an affected device. A successful exploit could cause an affected device to continuously consume memory and eventually result in a memory allocation failure that leads to a crash, triggering a reload of the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105398http://www.securitytracker.com/id/1041737https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-cdp-memleakhttp://www.securityfocus.com/bid/105398http://www.securitytracker.com/id/1041737https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-cdp-memleak
2018-10-05
Published