CVE-2017-3824: Buffer Overflow
A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Routers running vulnerable versions of Cisco IOS XE are affected. More Information: CSCux40637. Known Affected Releases: 15.5(3)S 15.6(1)S. Known Fixed Releases: 15.5(3)S2 15.6(1)S1 15.6(2)S 15.6(2)SP 16.4(1).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOS XE (cBR Series Converged Broadband Routers)to a version that resolves this vulnerability.Fixed in 15.5(3)S2 - Upgrade
Upgrade
Cisco IOS XE (cBR Series Converged Broadband Routers)to a version that resolves this vulnerability.Fixed in 15.6(1)S1 - Upgrade
Upgrade
Cisco IOS XE (cBR Series Converged Broadband Routers)to a version that resolves this vulnerability.Fixed in 15.6(2)S - Upgrade
Upgrade
Cisco IOS XE (cBR Series Converged Broadband Routers)to a version that resolves this vulnerability.Fixed in 15.6(2)SP - Upgrade
Upgrade
Cisco IOS XE (cBR Series Converged Broadband Routers)to a version that resolves this vulnerability.Fixed in 16.4(1) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCux40637
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3824?
CVE-2017-3824 has been assigned a CVSS score that indicates it is a high severity vulnerability.
How do I fix CVE-2017-3824?
To fix CVE-2017-3824, update the Cisco cBR Series Converged Broadband Routers to a patched version of the Cisco IOS XE software.
What are the affected versions for CVE-2017-3824?
CVE-2017-3824 affects Cisco IOS XE versions 3.16.0, 3.16.1, and 3.17.0.
What type of attack does CVE-2017-3824 allow?
CVE-2017-3824 allows an unauthenticated remote attacker to cause the device to reload, leading to a denial of service condition.
Which Cisco devices are impacted by CVE-2017-3824?
CVE-2017-3824 specifically impacts Cisco cBR-8 Converged Broadband Routers running vulnerable versions of Cisco IOS XE.