7.8

CVE-2017-3856

A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the web user interface of the software is enabled. By default, the web user interface is not enabled. Cisco Bug IDs: CSCup70353.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xe Version3.1.0s
CiscoIos Xe Version3.1.0sg
CiscoIos Xe Version3.1.1s
CiscoIos Xe Version3.1.1sg
CiscoIos Xe Version3.1.2s
CiscoIos Xe Version3.1.3as
CiscoIos Xe Version3.1.3s
CiscoIos Xe Version3.1.4as
CiscoIos Xe Version3.1.4s
CiscoIos Xe Version3.1s
CiscoIos Xe Version3.1sg
CiscoIos Xe Version3.2.0ja
CiscoIos Xe Version3.2.0se
CiscoIos Xe Version3.2.0sg
CiscoIos Xe Version3.2.0xo
CiscoIos Xe Version3.2.1s
CiscoIos Xe Version3.2.1se
CiscoIos Xe Version3.2.1sg
CiscoIos Xe Version3.2.1xo
CiscoIos Xe Version3.2.2s
CiscoIos Xe Version3.2.2se
CiscoIos Xe Version3.2.2sg
CiscoIos Xe Version3.2.3se
CiscoIos Xe Version3.2.3sg
CiscoIos Xe Version3.2.4sg
CiscoIos Xe Version3.2.5sg
CiscoIos Xe Version3.2.6sg
CiscoIos Xe Version3.2.7sg
CiscoIos Xe Version3.2.8sg
CiscoIos Xe Version3.2.9sg
CiscoIos Xe Version3.2.11sg
CiscoIos Xe Version3.2ja
CiscoIos Xe Version3.2s
CiscoIos Xe Version3.2se
CiscoIos Xe Version3.2sg
CiscoIos Xe Version3.2xo
CiscoIos Xe Version3.3.0s
CiscoIos Xe Version3.3.0se
CiscoIos Xe Version3.3.0sg
CiscoIos Xe Version3.3.0sq
CiscoIos Xe Version3.3.0xo
CiscoIos Xe Version3.3.1s
CiscoIos Xe Version3.3.1se
CiscoIos Xe Version3.3.1sg
CiscoIos Xe Version3.3.1sq
CiscoIos Xe Version3.3.1xo
CiscoIos Xe Version3.3.2s
CiscoIos Xe Version3.3.2se
CiscoIos Xe Version3.3.2sg
CiscoIos Xe Version3.3.2xo
CiscoIos Xe Version3.3.3se
CiscoIos Xe Version3.3.4se
CiscoIos Xe Version3.3.5se
CiscoIos Xe Version3.3s
CiscoIos Xe Version3.3se
CiscoIos Xe Version3.3sg
CiscoIos Xe Version3.3sq
CiscoIos Xe Version3.3xo
CiscoIos Xe Version3.4.0as
CiscoIos Xe Version3.4.0s
CiscoIos Xe Version3.4.0sg
CiscoIos Xe Version3.4.0sq
CiscoIos Xe Version3.4.1s
CiscoIos Xe Version3.4.1sg
CiscoIos Xe Version3.4.1sq
CiscoIos Xe Version3.4.2s
CiscoIos Xe Version3.4.2sg
CiscoIos Xe Version3.4.3s
CiscoIos Xe Version3.4.3sg
CiscoIos Xe Version3.4.4s
CiscoIos Xe Version3.4.4sg
CiscoIos Xe Version3.4.5s
CiscoIos Xe Version3.4.5sg
CiscoIos Xe Version3.4.6s
CiscoIos Xe Version3.4.6sg
CiscoIos Xe Version3.4.7sg
CiscoIos Xe Version3.4.8sg
CiscoIos Xe Version3.4s
CiscoIos Xe Version3.4sg
CiscoIos Xe Version3.4sq
CiscoIos Xe Version3.5.0e
CiscoIos Xe Version3.5.0s
CiscoIos Xe Version3.5.0sq
CiscoIos Xe Version3.5.1e
CiscoIos Xe Version3.5.1s
CiscoIos Xe Version3.5.1sq
CiscoIos Xe Version3.5.2e
CiscoIos Xe Version3.5.2s
CiscoIos Xe Version3.5.2sq
CiscoIos Xe Version3.5.3e
CiscoIos Xe Version3.5.3sq
CiscoIos Xe Version3.5.4sq
CiscoIos Xe Version3.5.5sq
CiscoIos Xe Version3.5e
CiscoIos Xe Version3.5s
CiscoIos Xe Version3.5sq
CiscoIos Xe Version3.6.0e
CiscoIos Xe Version3.6.0s
CiscoIos Xe Version3.6.1e
CiscoIos Xe Version3.6.1s
CiscoIos Xe Version3.6.2ae
CiscoIos Xe Version3.6.2s
CiscoIos Xe Version3.6.3e
CiscoIos Xe Version3.6.4e
CiscoIos Xe Version3.6.5ae
CiscoIos Xe Version3.6.5be
CiscoIos Xe Version3.6.5e
CiscoIos Xe Version3.6e
CiscoIos Xe Version3.6s
CiscoIos Xe Version3.7.0bs
CiscoIos Xe Version3.7.0e
CiscoIos Xe Version3.7.0s
CiscoIos Xe Version3.7.1e
CiscoIos Xe Version3.7.1s
CiscoIos Xe Version3.7.2e
CiscoIos Xe Version3.7.2s
CiscoIos Xe Version3.7.2ts
CiscoIos Xe Version3.7.3e
CiscoIos Xe Version3.7.3s
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.4s
CiscoIos Xe Version3.7.5s
CiscoIos Xe Version3.7.6s
CiscoIos Xe Version3.7.7s
CiscoIos Xe Version3.7e
CiscoIos Xe Version3.7s
CiscoIos Xe Version3.8.0e
CiscoIos Xe Version3.8.0ex
CiscoIos Xe Version3.8.0s
CiscoIos Xe Version3.8.1e
CiscoIos Xe Version3.8.1s
CiscoIos Xe Version3.8.2e
CiscoIos Xe Version3.8.2s
CiscoIos Xe Version3.8e
CiscoIos Xe Version3.8ex
CiscoIos Xe Version3.8s
CiscoIos Xe Version3.9.0e
CiscoIos Xe Version3.9.0s
CiscoIos Xe Version3.9.1s
CiscoIos Xe Version3.9.2s
CiscoIos Xe Version3.9e
CiscoIos Xe Version3.9s
CiscoIos Xe Version3.10.0s
CiscoIos Xe Version3.10.1s
CiscoIos Xe Version3.10.1xbs
CiscoIos Xe Version3.10.2s
CiscoIos Xe Version3.10.2ts
CiscoIos Xe Version3.10.3s
CiscoIos Xe Version3.10.4s
CiscoIos Xe Version3.10.5s
CiscoIos Xe Version3.10.6s
CiscoIos Xe Version3.10.7s
CiscoIos Xe Version3.10.8s
CiscoIos Xe Version3.10s
CiscoIos Xe Version3.11.0s
CiscoIos Xe Version3.11.1s
CiscoIos Xe Version3.11.2s
CiscoIos Xe Version3.11.3s
CiscoIos Xe Version3.11.4s
CiscoIos Xe Version3.11s
CiscoIos Xe Version3.12.0as
CiscoIos Xe Version3.12.0s
CiscoIos Xe Version3.12.1s
CiscoIos Xe Version3.12.2s
CiscoIos Xe Version3.12.3s
CiscoIos Xe Version3.12.4s
CiscoIos Xe Version3.12s
CiscoIos Xe Version3.13.0as
CiscoIos Xe Version3.13.0s
CiscoIos Xe Version3.13.1s
CiscoIos Xe Version3.13.2as
CiscoIos Xe Version3.13.2s
CiscoIos Xe Version3.13.3s
CiscoIos Xe Version3.13.4s
CiscoIos Xe Version3.13s
CiscoIos Xe Version3.14.0s
CiscoIos Xe Version3.14.1s
CiscoIos Xe Version3.14.2s
CiscoIos Xe Version3.14.3s
CiscoIos Xe Version3.14.4s
CiscoIos Xe Version3.14s
CiscoIos Xe Version3.15.0s
CiscoIos Xe Version3.15.1cs
CiscoIos Xe Version3.15.1s
CiscoIos Xe Version3.15.2s
CiscoIos Xe Version3.15.3s
CiscoIos Xe Version3.15s
CiscoIos Xe Version3.16.0cs
CiscoIos Xe Version3.16.0s
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.1s
CiscoIos Xe Version3.16s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1as
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.17.2s
CiscoIos Xe Version3.17.3s
CiscoIos Xe Version3.17s
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.