PT-2018-3860 · Cisco · Cisco Ios Xe
Published
2018-06-06
·
Updated
2023-01-24
·
CVE-2018-0315
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1
Description
A vulnerability in the authentication, authorization, and accounting (AAA) security services could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect memory operations that the affected software performs when the software parses a
username during login authentication. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device or cause the affected device to reload, resulting in a DoS condition.Recommendations
For Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1, update to a newer version that addresses this vulnerability.
As a temporary workaround, consider restricting access to the AAA security services until a patch is available.
Avoid using the
username parameter in the affected login authentication process until the issue is resolved.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe