CVE-2018-0472
Cisco IOS XE Software and Cisco ASA 5500-X Series Adaptive Security Appliance IPsec Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to improper processing of malformed IPsec Authentication Header (AH) or Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by sending malformed IPsec packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.
Una vulnerabilidad en el código del controlador IPsec de múltiples plataformas Cisco IOS XE Software y Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) podría permitir que un atacante remoto no autenticado provoque la recarga del dispositivo. La vulnerabilidad se debe al procesamiento incorrecto de una cabecera de autenticación (AH) IPsec mal formada o de paquetes ESP (Encapsulating Security Payload). Un atacante podría explotar esta vulnerabilidad enviando paquetes IPsec mal formados para que los procese el dispositivo afectado. Su explotación podría permitir que el atacante provoque la recarga del dispositivo afectado.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2017-11-27 CVE Reserved
- 2018-10-05 CVE Published
- 2024-07-11 EPSS Updated
- 2024-11-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105418 | Third Party Advisory | |
http://www.securitytracker.com/id/1041735 | Third Party Advisory | |
http://www.securitytracker.com/id/1041737 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-19-094-04 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-ipsec | 2019-04-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 15.5\(3\)s5.36 Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s5.36" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.8.1 Search vendor "Cisco" for product "Ios Xe" and version "16.8.1" | - |
Affected
|