CVE-2019-1747: Cisco IOS and IOS XE Software Short Message Service Denial of Service Vulnerability
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of SMS protocol data units (PDUs) that are encoded with a special character set. An attacker could exploit this vulnerability by sending a malicious SMS message to an affected device. A successful exploit could allow the attacker to cause the wireless WAN (WWAN) cellular interface module on an affected device to crash, resulting in a DoS condition that would require manual intervention to restore normal operating conditions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1747?
CVE-2019-1747 has a high severity rating as it allows unauthorized remote attackers to cause a denial of service.
How do I fix CVE-2019-1747?
To fix CVE-2019-1747, upgrade affected Cisco IOS or IOS XE software to a version that addresses the vulnerability.
What devices are affected by CVE-2019-1747?
CVE-2019-1747 affects specific versions of Cisco IOS 15.8(3)m and Cisco IOS XE 16.10.1.
Can CVE-2019-1747 be exploited remotely?
Yes, CVE-2019-1747 can be exploited remotely by unauthenticated attackers.
What impact does CVE-2019-1747 have on network operations?
CVE-2019-1747 can lead to a denial of service condition, potentially disrupting network operations.