PT-2017-17186 · Cisco · Cisco Ios Xe

Published

2017-04-19

·

Updated

2019-10-03

·

CVE-2017-6615

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE versions 3.16
Description A vulnerability in the Simple Network Management Protocol (SNMP) subsystem could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The issue is due to a race condition that occurs when the affected software processes an SNMP read request containing certain criteria for a specific object ID (OID) and an active crypto session is disconnected on the affected device. An attacker who can authenticate to the device could trigger this issue by issuing an SNMP request for a specific OID, causing the device to restart due to an attempt to access an invalid memory region.
Recommendations For Cisco IOS XE version 3.16, update the software to a version that fixes the issue, as there are no workarounds that address this vulnerability. As a temporary workaround, consider restricting access to the SNMP subsystem to minimize the risk of exploitation.

Fix

DoS

Race Condition

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6615

Affected Products

Cisco Ios Xe