First published: Wed Mar 27 2019(Updated: )
A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with the Easy Virtual Switching System. An attacker could exploit this vulnerability by sending a specially crafted CDP packet. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-evss This advisory is part of the March 27, 2019, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 17 Cisco Security Advisories that describe 19 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2019 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.
Credit: This vulnerability was found during the resolution a Cisco TAC support case
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS and IOS XE Software | ||
Cisco Catalyst 4500 Series Switches |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-20190327-evss is high due to the potential for an unauthenticated attacker to cause a denial of service.
To fix cisco-sa-20190327-evss, you should update your Cisco IOS XE Software and Catalyst 4500 Series Switches to the latest patched version.
The cisco-sa-20190327-evss vulnerability is caused by incomplete error handling in the Easy Virtual Switching System of Cisco IOS XE Software.
Cisco Catalyst 4500 Series Switches running affected versions of Cisco IOS XE Software are impacted by the cisco-sa-20190327-evss vulnerability.
The impact of cisco-sa-20190327-evss on your network can result in a switch reload, leading to a denial of service for users.