CVE-2017-3856: High severity Cisco IOS XE vulnerability
A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the web user interface of the software is enabled. By default, the web user interface is not enabled. Cisco Bug IDs: CSCup70353.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOS XE Softwareto a version that resolves this vulnerability.Fixed in 3.1 through 3.17Patch CSCup70353 - Configuration
Ensure the web user interface is not enabled (by default it is not enabled). This vulnerability affects Cisco IOS XE releases only if the web UI is enabled.
Cisco IOS XE web user interface web user interface enabled = disabled - Compensating control
Restrict access to the management interface/web user interface to the restricted management network (limit to trusted sources) since exploitation requires access to the management interface.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3856?
CVE-2017-3856 has a CVSS score of 7.5, indicating it is a high severity vulnerability.
How do I fix CVE-2017-3856?
To fix CVE-2017-3856, upgrade your Cisco IOS XE to a version that applies the necessary patches.
What can an attacker do exploiting CVE-2017-3856?
An attacker exploiting CVE-2017-3856 can cause an affected device to reload, leading to denial of service.
Which versions of Cisco IOS XE are affected by CVE-2017-3856?
CVE-2017-3856 affects Cisco IOS XE versions 3.1 through 3.17.
Is there a workaround for CVE-2017-3856?
Currently, the recommended action is to apply the software updates; no specific workaround is provided.