PT-2017-2015 · Cisco · Cisco Ios Xe+1

Published

2017-03-22

·

Updated

2020-09-04

·

CVE-2017-3864

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.2, 12.4, and 15.0 through 15.6 Cisco IOS XE versions 3.3 through 3.7
Description A vulnerability in the DHCP client implementation could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during the parsing of a crafted DHCP packet. An attacker could exploit this vulnerability by sending crafted DHCP packets to an affected device that is configured as a DHCP client. A successful exploit could allow the attacker to cause a reload of an affected device, resulting in a DoS condition.
Recommendations For Cisco IOS versions 12.2, 12.4, and 15.0 through 15.6, update to a fixed release of Cisco IOS Software. For Cisco IOS XE versions 3.3 through 3.7, update to a fixed release of Cisco IOS XE Software. As a temporary workaround, consider restricting the use of the DHCP client configuration to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01182
CVE-2017-3864

Affected Products

Cisco Ios
Cisco Ios Xe