CVE-2019-1738: Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1738?
CVE-2019-1738 has a high severity rating, allowing attackers to cause impacted devices to reload without authentication.
How do I fix CVE-2019-1738?
To fix CVE-2019-1738, upgrade your Cisco IOS Software to a version that addresses this vulnerability as outlined in Cisco's advisory.
What products are affected by CVE-2019-1738?
CVE-2019-1738 affects various versions of Cisco IOS and IOS XE software, specifically some versions in 15.1, 15.2, 15.3, 15.5, and 15.6.
Can CVE-2019-1738 be exploited remotely?
Yes, CVE-2019-1738 can be exploited remotely by unauthenticated attackers through crafted DNS packets.
What measures should I take regarding CVE-2019-1738?
Users should apply the recommended patches or update to secure software versions to mitigate the risks associated with CVE-2019-1738.