First published: Fri Feb 03 2017(Updated: )
A vulnerability in Simple Network Management Protocol (SNMP) functions of Cisco ASR 1000 Series Aggregation Services Routers running Cisco IOS XE Software Release 3.13.6S, 3.16.2S, or 3.17.1S could allow an authenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. More Information: CSCux68796. Known Affected Releases: 15.5(3)S2.1 15.6(1)S1.1. Known Fixed Releases: 15.4(3)S6.1 15.4(3)S6.2 15.5(3)S2.2 15.5(3)S3 15.6(0.22)S0.23 15.6(1)S2 16.2(0.295) 16.3(0.94) 15.5.3S3.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =3.13.6s | |
Cisco IOS XE Web UI | =3.16.2s | |
Cisco IOS XE Web UI | =3.17.1s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3820 is considered a medium severity vulnerability due to its potential to cause high CPU usage on affected devices.
To fix CVE-2017-3820, upgrade to a patched version of Cisco IOS XE that addresses this vulnerability.
CVE-2017-3820 affects Cisco ASR 1000 Series Aggregation Services Routers running specific versions of Cisco IOS XE Software.
CVE-2017-3820 could allow an authenticated remote attacker to exploit SNMP functions and cause high CPU utilization.
Yes, CVE-2017-3820 is remotely exploitable, but the attacker must be authenticated to exploit this vulnerability.