PT-2018-3860 · Cisco · Cisco Ios Xe

Published

2018-06-06

·

Updated

2023-01-24

·

CVE-2018-0315

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1
Description A vulnerability in the authentication, authorization, and accounting (AAA) security services could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect memory operations that the affected software performs when the software parses a username during login authentication. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device or cause the affected device to reload, resulting in a DoS condition.
Recommendations For Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1, update to a newer version that addresses this vulnerability. As a temporary workaround, consider restricting access to the AAA security services until a patch is available. Avoid using the username parameter in the affected login authentication process until the issue is resolved.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-00712
CVE-2018-0315

Affected Products

Cisco Ios Xe