PT-2019-15173 · Cisco · Catalyst 4500 Series Switches+1

Published

2019-03-27

·

Updated

2019-10-09

·

CVE-2019-1750

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software on Catalyst 4500 Series Switches (affected versions not specified)
Description The issue is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with the Easy Virtual Switching System. An unauthenticated, adjacent attacker could exploit this by sending a specially crafted CDP packet, causing the device to reload and resulting in a denial of service (DoS) condition.
Recommendations For Cisco IOS XE Software on Catalyst 4500 Series Switches, apply the software updates released by Cisco that address this issue. As a temporary workaround, consider implementing workarounds that address this vulnerability, as described in the Cisco Security Advisory.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1750

Affected Products

Catalyst 4500 Series Switches
Cisco Ios Xe