CVE-2017-3861: Buffer Overflow
Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Cisco IOS Software and Cisco IOS XE Software support EnergyWise for IPv4 communication. Only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger these vulnerabilities. IPv6 packets cannot be used to trigger these vulnerabilities. Cisco Bug ID CSCut47751.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Because only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger the vulnerabilities, configure/verify devices so they are not configured as EnergyWise domain members unless required, and prevent crafted EnergyWise traffic from reaching any device that is configured as a domain member.
Cisco EnergyWise (IPv4) domain member behavior EnergyWise packet processing for non-domain-member destination = Restrict to only allow EnergyWise packets destined to a device configured as an EnergyWise domain member - Compensating control
Ensure EnergyWise IPv4 packets are not processed by limiting which IPv4 sources/networks can send EnergyWise packets to devices configured as EnergyWise domain members (these vulnerabilities can be triggered only by crafted IPv4 EnergyWise packets destined to an EnergyWise domain member).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3861?
CVE-2017-3861 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2017-3861?
To fix CVE-2017-3861, the affected devices must be updated to the recommended software versions provided by Cisco.
What devices are impacted by CVE-2017-3861?
CVE-2017-3861 affects various versions of Cisco IOS and IOS XE, specifically from version 12.2 through 15.6.
What are the potential consequences of exploiting CVE-2017-3861?
Exploitation of CVE-2017-3861 could allow an unauthenticated remote attacker to cause a buffer overflow or reload the device, leading to a denial of service.
Can CVE-2017-3861 be exploited remotely?
Yes, CVE-2017-3861 can be exploited by an unauthenticated remote attacker, which significantly increases its risk.