First published: Wed Mar 27 2019(Updated: )
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of SMS protocol data units (PDUs) that are encoded with a special character set. An attacker could exploit this vulnerability by sending a malicious SMS message to an affected device. A successful exploit could allow the attacker to cause the wireless WAN (WWAN) cellular interface module on an affected device to crash, resulting in a DoS condition that would require manual intervention to restore normal operating conditions. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-sms-dos This advisory is part of the March 27, 2019, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 17 Cisco Security Advisories that describe 19 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2019 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.
Credit: This vulnerability was found during the resolution a Cisco TAC support case
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | ||
Cisco IOS XE Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The cisco-sa-20190327-sms-dos vulnerability has a high severity rating due to its potential for triggering a denial of service condition.
To fix the cisco-sa-20190327-sms-dos vulnerability, it is recommended to apply the latest patches and updates available for Cisco IOS and IOS XE Software.
Cisco IOS Software and Cisco IOS XE Software devices are affected by the cisco-sa-20190327-sms-dos vulnerability.
Yes, the cisco-sa-20190327-sms-dos vulnerability can be exploited by an unauthenticated remote attacker.
The cisco-sa-20190327-sms-dos vulnerability facilitates a denial of service (DoS) attack.