7.7
CVE-2018-0209
- EPSS 0.67%
- Veröffentlicht 08.03.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:44
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Small Business 500 Series Stackable Managed Switches Firmware Version2.2.5.68
Cisco ≫ Sf500-24 Version-
Cisco ≫ Sf500-24mp Version-
Cisco ≫ Sf500-24p Version-
Cisco ≫ Sf500-48 Version-
Cisco ≫ Sf500-48mp Version-
Cisco ≫ Sf500-48p Version-
Cisco ≫ Sg500-28 Version-
Cisco ≫ Sg500-28mpp Version-
Cisco ≫ Sg500-28p Version-
Cisco ≫ Sg500-52 Version-
Cisco ≫ Sg500-52mp Version-
Cisco ≫ Sg500-52p Version-
Cisco ≫ Sg500x-24 Version-
Cisco ≫ Sg500x-24mpp Version-
Cisco ≫ Sg500x-24p Version-
Cisco ≫ Sg500x-48 Version-
Cisco ≫ Sg500x-48mp Version-
Cisco ≫ Sg500x-48p Version-
Cisco ≫ Sg500xg-8f8t Version-
Cisco ≫ Sf500-24mp Version-
Cisco ≫ Sf500-24p Version-
Cisco ≫ Sf500-48 Version-
Cisco ≫ Sf500-48mp Version-
Cisco ≫ Sf500-48p Version-
Cisco ≫ Sg500-28 Version-
Cisco ≫ Sg500-28mpp Version-
Cisco ≫ Sg500-28p Version-
Cisco ≫ Sg500-52 Version-
Cisco ≫ Sg500-52mp Version-
Cisco ≫ Sg500-52p Version-
Cisco ≫ Sg500x-24 Version-
Cisco ≫ Sg500x-24mpp Version-
Cisco ≫ Sg500x-24p Version-
Cisco ≫ Sg500x-48 Version-
Cisco ≫ Sg500x-48mp Version-
Cisco ≫ Sg500x-48p Version-
Cisco ≫ Sg500xg-8f8t Version-
Cisco ≫ Small Business 500 Series Stackable Managed Switches Firmware Version2.3.0.130
Cisco ≫ Sf500-24 Version-
Cisco ≫ Sf500-24mp Version-
Cisco ≫ Sf500-24p Version-
Cisco ≫ Sf500-48 Version-
Cisco ≫ Sf500-48mp Version-
Cisco ≫ Sf500-48p Version-
Cisco ≫ Sg500-28 Version-
Cisco ≫ Sg500-28mpp Version-
Cisco ≫ Sg500-28p Version-
Cisco ≫ Sg500-52 Version-
Cisco ≫ Sg500-52mp Version-
Cisco ≫ Sg500-52p Version-
Cisco ≫ Sg500x-24 Version-
Cisco ≫ Sg500x-24mpp Version-
Cisco ≫ Sg500x-24p Version-
Cisco ≫ Sg500x-48 Version-
Cisco ≫ Sg500x-48mp Version-
Cisco ≫ Sg500x-48p Version-
Cisco ≫ Sg500xg-8f8t Version-
Cisco ≫ Sf500-24mp Version-
Cisco ≫ Sf500-24p Version-
Cisco ≫ Sf500-48 Version-
Cisco ≫ Sf500-48mp Version-
Cisco ≫ Sf500-48p Version-
Cisco ≫ Sg500-28 Version-
Cisco ≫ Sg500-28mpp Version-
Cisco ≫ Sg500-28p Version-
Cisco ≫ Sg500-52 Version-
Cisco ≫ Sg500-52mp Version-
Cisco ≫ Sg500-52p Version-
Cisco ≫ Sg500x-24 Version-
Cisco ≫ Sg500x-24mpp Version-
Cisco ≫ Sg500x-24p Version-
Cisco ≫ Sg500x-48 Version-
Cisco ≫ Sg500x-48mp Version-
Cisco ≫ Sg500x-48p Version-
Cisco ≫ Sg500xg-8f8t Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.67% | 0.705 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
|
| nvd@nist.gov | 6.8 | 8 | 6.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.