PT-2018-2794 · Cisco · Cisco Ios

Published

2018-03-28

·

Updated

2025-01-27

·

CVE-2018-0161

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS Software (affected versions not specified)
Description A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device, potentially causing the device to restart due to a SYS-3-CPUHOG.
Recommendations For Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, and Cisco Catalyst Digital Building Series Switches 8U, update to a fixed release of Cisco IOS Software. As a temporary workaround, consider restricting access to the SNMP subsystem to minimize the risk of exploitation. Avoid using the ciscoFlashMIB OID in SNMP GET requests until the issue is resolved. Apply the workarounds described in the Cisco Security Advisory to address this vulnerability.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01883
CVE-2018-0161

Affected Products

Cisco Ios