CVE-2018-0177: High severity cisco ios xe vulnerability
A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IPv4 packets. An attacker could exploit this vulnerability by sending specific IPv4 packets to an IPv4 address on an affected device. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. If the switch does not reboot when under attack, it would require manual intervention to reload the device. This vulnerability affects Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches that are running Cisco IOS XE Software Release 16.1.1 or later, until the first fixed release, and are configured with an IPv4 address. Cisco Bug IDs: CSCvd80714.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0177?
CVE-2018-0177 has been assigned a medium severity rating due to its potential to cause high CPU utilization and device reloads.
How do I fix CVE-2018-0177?
To fix CVE-2018-0177, upgrade to a patched version of Cisco IOS XE Software, specifically versions denali-16.3.2 or denali-16.3.4 and later.
What devices are affected by CVE-2018-0177?
CVE-2018-0177 affects Cisco Catalyst 3850 and 3650 Series Switches running specific versions of IOS XE.
Can CVE-2018-0177 be exploited remotely?
Yes, CVE-2018-0177 can be exploited by an unauthenticated remote attacker.
What are the potential impacts of CVE-2018-0177?
The impact of CVE-2018-0177 includes high CPU utilization, generation of traceback messages, or device reloads.