Vulnerability CVE-2019-1737


Published: 2019-03-27

Description:
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual denial of service (DoS) condition on the affected device. The vulnerability is due to improper socket resources handling in the IP SLA responder application code. An attacker could exploit this vulnerability by sending crafted IP SLA packets to an affected device. An exploit could allow the attacker to cause an interface to become wedged, resulting in an eventual denial of service (DoS) condition on the affected device.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

Vendor: Cisco
Product: Ios xe 
Version:
3.9.2s
3.9.2e
3.9.2be
3.9.1s
3.9.1e
3.9.1as
3.9.0s
3.9.0e
3.9.0as
3.8.5e
3.8.5ae
3.8.4e
3.8.3e
3.8.2s
3.8.2e
3.8.1s
3.8.1e
3.8.0s
3.8.0e
3.7.8s
3.7.7s
3.7.6s
3.7.5s
3.7.5e
3.7.4s
3.7.4e
3.7.4as
3.7.3s
3.7.3e
3.7.2ts
3.7.2s
3.7.2e
3.7.1s
3.7.1e
3.7.1as
3.7.0s
3.7.0e
3.7.0bs
3.6.7e
3.6.7be
3.6.7ae
3.6.6e
3.6.5e
3.6.5be
3.6.5ae
3.6.4e
3.6.3e
3.6.2e
3.6.2ae
3.6.1e
3.6.0e
3.6.0be
3.6.0ae
3.5.3e
3.5.2e
3.5.1e
3.5.0e
3.4.8sg
3.4.7sg
3.4.6sg
3.4.5sg
3.4.4sg
3.4.3sg
3.4.2sg
3.4.1sg
3.4.0sg
3.3.5se
3.3.4se
3.3.3se
3.3.2xo
3.3.2se
3.3.1xo
3.3.1se
3.3.0xo
3.3.0se
3.2.3se
3.2.2se
3.2.1se
3.2.0se
3.2.0ja
3.18.4s
3.18.3s
3.18.2sp
3.18.2s
3.18.2asp
3.18.1sp
3.18.1s
3.18.1isp
3.18.1hsp
3.18.1gsp
3.18.1csp
3.18.1bsp
3.18.1asp
3.18.0sp
3.18.0s
3.18.0as
3.17.4s
3.17.3s
3.17.1s
3.17.1as
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete

 References:
http://www.securityfocus.com/bid/107604
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-ipsla-dos

Related CVE
CVE-2019-1780
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevate...
CVE-2019-1860
A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center....
CVE-2019-1858
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could c...
CVE-2019-1853
A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software...
CVE-2019-1851
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE....
CVE-2019-1849
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition...
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent atta...
CVE-2019-1833
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due ...

Copyright 2019, cxsecurity.com

 

Back to Top