CVE-2019-1869
published 2019-06-20CVE-2019-1869: A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.64%
83.8th percentile
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of this vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_asr_5000_series_software | >= unspecified < 21.11.1 | 21.11.1 |
| cisco | staros | — | — |
| cisco | staros | >= 21.10 < 21.10.2 | 21.10.2 |
| cisco | staros | >= 21.11 < 21.11.1 | 21.11.1 |
| cisco | staros | >= 21.6 < 21.6.13 | 21.6.13 |
| cisco | staros | >= 21.6b < 21.6b.16 | 21.6b.16 |
| cisco | staros | >= 21.7 < 21.7.11 | 21.7.11 |
| cisco | staros | >= 21.8 < 21.8.10 | 21.8.10 |
| cisco | staros | >= 21.9 < 21.9.7 | 21.9.7 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco StarOS Denial of Service Vulnerability
vendor_cisco·2019-06-19·CVSS 8.6
CVE-2019-1869 [HIGH] CWE-824 Cisco StarOS Denial of Service Vulnerability
Cisco StarOS Denial of Service Vulnerability
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition.
The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface.
The device may have to be manually reloaded to recover from exploitation of this vulnerabili
Cisco
Cisco StarOS Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1869 Cisco StarOS Denial of Service Vulnerability
CVE-2019-1869: Cisco StarOS Denial of Service Vulnerability
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of th
GHSA
GHSA-r863-66v2-rjq3: A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unaut
ghsa_unreviewed·2022-05-24
CVE-2019-1869 [HIGH] CWE-824 GHSA-r863-66v2-rjq3: A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unaut
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-20
Published