7.7

CVE-2018-0209

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoSmall Business 500 Series Stackable Managed Switches Firmware Version2.2.5.68
   CiscoSf500-24 Version-
   CiscoSf500-24mp Version-
   CiscoSf500-24p Version-
   CiscoSf500-48 Version-
   CiscoSf500-48mp Version-
   CiscoSf500-48p Version-
   CiscoSg500-28 Version-
   CiscoSg500-28mpp Version-
   CiscoSg500-28p Version-
   CiscoSg500-52 Version-
   CiscoSg500-52mp Version-
   CiscoSg500-52p Version-
   CiscoSg500x-24 Version-
   CiscoSg500x-24mpp Version-
   CiscoSg500x-24p Version-
   CiscoSg500x-48 Version-
   CiscoSg500x-48mp Version-
   CiscoSg500x-48p Version-
   CiscoSg500xg-8f8t Version-
CiscoSmall Business 500 Series Stackable Managed Switches Firmware Version2.3.0.130
   CiscoSf500-24 Version-
   CiscoSf500-24mp Version-
   CiscoSf500-24p Version-
   CiscoSf500-48 Version-
   CiscoSf500-48mp Version-
   CiscoSf500-48p Version-
   CiscoSg500-28 Version-
   CiscoSg500-28mpp Version-
   CiscoSg500-28p Version-
   CiscoSg500-52 Version-
   CiscoSg500-52mp Version-
   CiscoSg500-52p Version-
   CiscoSg500x-24 Version-
   CiscoSg500x-24mpp Version-
   CiscoSg500x-24p Version-
   CiscoSg500x-48 Version-
   CiscoSg500x-48mp Version-
   CiscoSg500x-48p Version-
   CiscoSg500xg-8f8t Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.