PT-2019-1729 · Cisco · Cisco Ios Xe+1

Published

2019-03-27

·

Updated

2022-03-18

·

CVE-2019-1737

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS Software and Cisco IOS XE software (affected versions not specified)
Description A vulnerability in the processing of IP Service Level Agreement (SLA) packets could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual denial of service (DoS) condition on the affected device. The vulnerability is due to improper socket resources handling in the IP SLA responder application code. An attacker could exploit this vulnerability by sending crafted IP SLA packets to an affected device, causing an interface to become wedged and resulting in an eventual denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01361
CVE-2019-1737

Affected Products

Cisco Ios
Cisco Ios Xe