CVE-2018-0480
published 2018-10-05CVE-2018-0480: A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash…
PriorityP424medium6.1CVSS 3.0
AVAACHPRNUINSCCNINAH
EPSS
0.52%
41.2th percentile
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Errdisable Denial of Service Vulnerability
vendor_cisco·2018-09-26·CVSS 7.4
CVE-2018-0480 [HIGH] CWE-362 Cisco IOS XE Software Errdisable Denial of Service Vulnerability
Cisco IOS XE Software Errdisable Denial of Service Vulnerability
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition.
The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at t
Cisco
Cisco IOS XE Software Errdisable Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0480 Cisco IOS XE Software Errdisable Denial of Service Vulnerability
CVE-2018-0480: Cisco IOS XE Software Errdisable Denial of Service Vulnerability
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-362, CWE-362
Bug IDs: CSCvh13611
GHSA
GHSA-2q4r-gmc8-6577: A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to c
ghsa_unreviewed·2022-05-13
CVE-2018-0480 [MEDIUM] CWE-362 GHSA-2q4r-gmc8-6577: A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to c
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
bugzilla·2018-01-15·CVSS 7.5
CVE-2018-1048 [HIGH] CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
It was found that the AJP connector in undertow does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0478 https://access.redhat.com/errata/RHSA-2018:0478
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
Via RHSA-2018:0480 https://access.redhat.com/errata/RHSA-2018:0480
---
This issue has been addressed in the following produ
Bugzilla
CVE-2017-12196 undertow: Client can use bogus uri in Digest authentication
bugzilla·2017-10-17·CVSS 4.8
CVE-2017-12196 [MEDIUM] CVE-2017-12196 undertow: Client can use bogus uri in Digest authentication
CVE-2017-12196 undertow: Client can use bogus uri in Digest authentication
When using a "Digest" authentication, server does not ensure that value of the "uri" attribute in "Authorization" header matches URI in HTTP request line. This can be exploitedby an attacker as a MITM attack to access desired content on server.
Discussion:
Acknowledgments:
Name: Jan Stourac (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0478 https://access.redhat.com/errata/RHSA-2018:0478
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
Via RHSA-2018:0480 https://access.redhat.com/errata/RHSA-2018:0480
---
This issue has been addressed in the follo
http://www.securityfocus.com/bid/105400http://www.securitytracker.com/id/1041737https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-errdisablehttp://www.securityfocus.com/bid/105400http://www.securitytracker.com/id/1041737https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-errdisable
2018-10-05
Published