8.6

CVE-2017-3860

Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Cisco IOS Software and Cisco IOS XE Software support EnergyWise for IPv4 communication. Only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger these vulnerabilities. IPv6 packets cannot be used to trigger these vulnerabilities. Cisco Bug ID CSCur29331.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version 3.2.1sg
Cisco ≫ Ios Xe Version 3.2.8sg
Cisco ≫ Ios Xe Version 3.3.1sg
Cisco ≫ Ios Xe Version 3.3.1sq
Cisco ≫ Ios Xe Version 3.4.1sg
Cisco ≫ Ios Xe Version 3.4.2sg
Cisco ≫ Ios Xe Version 3.4.3sg
Cisco ≫ Ios Xe Version 3.4.6sg
Cisco ≫ Ios Xe Version 3.4.8sg
Cisco ≫ Ios Xe Version 3.5.1e
Cisco ≫ Ios Xe Version 3.5.3e
Cisco ≫ Ios Xe Version 3.6.0e
Cisco ≫ Ios Xe Version 3.6.1e
Cisco ≫ Ios Xe Version 3.6.2ae
Cisco ≫ Ios Xe Version 3.6.2e
Cisco ≫ Ios Xe Version 3.6.4e
Cisco ≫ Ios Xe Version 3.6.5ae
Cisco ≫ Ios Xe Version 3.6.5e
Cisco ≫ Ios Xe Version 3.7.0e
Cisco ≫ Ios Xe Version 3.7.1e
Cisco ≫ Ios Xe Version 3.7.2e
Cisco ≫ Ios Xe Version 3.7.3e
Cisco ≫ Ios Xe Version 3.8.0e
Cisco ≫ Ios Xe Version 3.18.1sp
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.78% 0.845
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/97935
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038313
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170419-energywise
Vendor Advisory