8.8

CVE-2018-0167

Warnung
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Version 5.2.0.base
   Cisco ≫ Asr 9001 Version -
   Cisco ≫ Asr 9006 Version -
   Cisco ≫ Asr 9010 Version -
   Cisco ≫ Asr 9904 Version -
   Cisco ≫ Asr 9906 Version -
   Cisco ≫ Asr 9910 Version -
   Cisco ≫ Asr 9912 Version -
   Cisco ≫ Asr 9922 Version -
Cisco ≫ Ios Xe Version 5.2.0.base
   Cisco ≫ Asr 9001 Version -
   Cisco ≫ Asr 9006 Version -
   Cisco ≫ Asr 9010 Version -
   Cisco ≫ Asr 9904 Version -
   Cisco ≫ Asr 9906 Version -
   Cisco ≫ Asr 9910 Version -
   Cisco ≫ Asr 9912 Version -
   Cisco ≫ Asr 9922 Version -
Cisco ≫ Ios Xr Version >= 4.1 < 5.1.3
   Cisco ≫ Asr 9001 Version -
   Cisco ≫ Asr 9006 Version -
   Cisco ≫ Asr 9010 Version -
   Cisco ≫ Asr 9904 Version -
   Cisco ≫ Asr 9906 Version -
   Cisco ≫ Asr 9910 Version -
   Cisco ≫ Asr 9912 Version -
   Cisco ≫ Asr 9922 Version -
Cisco ≫ Ios Version <= 15.6.3m1
Cisco ≫ Ios Xe Version <= 15.6.3m1
Cisco ≫ Ios Version <= 15.2\(4a\)ea5
Cisco ≫ Ios Xe Version <= 15.2\(4a\)ea5

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Schwachstelle

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.38% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03
Third Party Advisory
US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05
Third Party Advisory
US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/103564
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1040586
Third Party Advisory
Broken Link
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0167
US Government Resource