CVE-2018-15377
published 2018-10-05CVE-2018-15377: A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software…
PriorityP348high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.59%
73.1th percentile
A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending invalid data to the Cisco Network Plug and Play agent on an affected device. A successful exploit could allow the attacker to cause a memory leak on the affected device, which could cause the device to reload.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_software | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5400/5410/5700 and ArmorStratix 5700
cisa_ics·2019-04-05·CVSS 8.6
[HIGH] Rockwell Automation Stratix 5400/5410/5700 and ArmorStratix 5700
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5400/5410/5700 and ArmorStratix 5700
Last RevisedApril 05, 2019
Alert CodeICSA-19-094-02
## 1. EXECUTIVE SUMMARY
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Stratix 5400/5410/5700, ArmorStratix 5700
- Vulnerability: Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to cause a memory leak on an affected device, which may cause the device to reload.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED P
Cisco
Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
vendor_cisco·2018-09-26·CVSS 6.8
CVE-2018-15377 [MEDIUM] CWE-401 Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device.
The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending invalid data to the Cisco Network Plug and Play agent on an affected device. A successful exploit could allow the attacker to cause a memory leak on the affected device, which could cause the device to reload.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec
Cisco
Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15377 Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
CVE-2018-15377: Cisco IOS and IOS XE Software Plug and Play Agent Memory Leak Vulnerability
A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending invalid data to the Cisco Network Plug and Play agent on an affected device. A successful exploit could allow the attacker to cause a memory leak on the affected device, which could cause the device to reload. There are no
CVSS: 3.0
CWE: CWE-401, CWE-401
Bug IDs: CSCvi30136
GHSA
GHSA-88ph-qq7q-p3qv: A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE
ghsa_unreviewed·2022-05-13
CVE-2018-15377 [HIGH] CWE-401 GHSA-88ph-qq7q-p3qv: A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE
A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending invalid data to the Cisco Network Plug and Play agent on an affected device. A successful exploit could allow the attacker to cause a memory leak on the affected device, which could cause the device to reload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ics-cert.us-cert.gov/advisories/ICSA-19-094-02https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-pnp-memleakhttps://ics-cert.us-cert.gov/advisories/ICSA-19-094-02https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-pnp-memleak
2018-10-05
Published