PT-2017-16144 · Cisco · Cisco Ios+1
Publicado
2017-03-20
·
Atualizado
2017-07-12
·
CVE-2017-3849
CVSS v3.1
7.4
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS Software versions 15.2 through 15.6
Cisco IOS XE Software versions 3.7 through 3.18, and 16
Description
A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics: (1) running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature; (2) configured as an autonomic registrar; (3) has a whitelist configured. An exploit could allow the attacker to cause the affected device to reload.
Recommendations
For Cisco IOS Software versions 15.2 through 15.6, update to a fixed release.
For Cisco IOS XE Software versions 3.7 through 3.18, and 16, update to a fixed release.
As a general mitigation measure, ensure that autonomic networking is configured with a whitelist and do not remove the whitelist as a workaround.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios
Cisco Ios Xe