CVE-2017-3862: Buffer Overflow
Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Cisco IOS Software and Cisco IOS XE Software support EnergyWise for IPv4 communication. Only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger these vulnerabilities. IPv6 packets cannot be used to trigger these vulnerabilities. Cisco Bug ID CSCuu76493.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Cisco Bug ID CSCuu76493 - Compensating control
Ensure EnergyWise is not reachable via IPv4 from untrusted networks, because only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger the EnergyWise parsing vulnerabilities.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3862?
The severity of CVE-2017-3862 is rated high, with a CVSS score of 8.6.
How do I fix CVE-2017-3862?
To mitigate CVE-2017-3862, users should upgrade their Cisco IOS or Cisco IOS XE to a fixed version as advised in the Cisco security advisory.
What vulnerabilities are associated with CVE-2017-3862?
CVE-2017-3862 includes multiple vulnerabilities in the EnergyWise module of Cisco IOS that could allow remote attackers to cause buffer overflows or device reloads.
Which Cisco devices are affected by CVE-2017-3862?
CVE-2017-3862 affects various versions of Cisco IOS versions 12.2 and 15.0 through 15.6, as well as Cisco IOS XE versions 3.2 through 3.18.
What risks are posed by CVE-2017-3862?
CVE-2017-3862 poses risks of denial of service (DoS) conditions, potentially leading to the disruption of network services.