8.6

CVE-2019-12647

A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by opening a TCP connection to specific ports and sending traffic over that connection. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xe Versionfuji-16.7.1
   Cisco1100 Version-
   Cisco4221 Version-
   Cisco4321 Version-
   Cisco4351 Version-
   Cisco4431 Version-
   Cisco4451-x Version-
   CiscoAsr 1000 Version-
   CiscoAsr 1001-hx Version-
   CiscoAsr 1001-x Version-
   CiscoAsr 1002-hx Version-
   CiscoAsr 1002-x Version-
   CiscoAsr 900 Version-
   CiscoAsr 920-10sz-pd Version-
   CiscoAsr 920-12cz-a Version-
   CiscoAsr 920-12cz-d Version-
   CiscoAsr 920-12sz-im Version-
   CiscoAsr 920-24sz-im Version-
   CiscoAsr 920-24sz-m Version-
   CiscoAsr 920-24tz-m Version-
   CiscoAsr 920-4sz-a Version-
   CiscoAsr 920-4sz-d Version-
   CiscoCloud Services Router 1000v Version-
   CiscoNcs 4201 Version-
   CiscoNcs 4202 Version-
   CiscoNcs 4206 Version-
   CiscoNcs 4216 Version-
   CiscoNetwork Convergence System 520 Version-
CiscoIos Xe Versionfuji-16.8.1
   Cisco1100 Version-
   Cisco4221 Version-
   Cisco4321 Version-
   Cisco4351 Version-
   Cisco4431 Version-
   Cisco4451-x Version-
   CiscoAsr 1000 Version-
   CiscoAsr 1001-hx Version-
   CiscoAsr 1001-x Version-
   CiscoAsr 1002-hx Version-
   CiscoAsr 1002-x Version-
   CiscoAsr 900 Version-
   CiscoAsr 920-10sz-pd Version-
   CiscoAsr 920-12cz-a Version-
   CiscoAsr 920-12cz-d Version-
   CiscoAsr 920-12sz-im Version-
   CiscoAsr 920-24sz-im Version-
   CiscoAsr 920-24sz-m Version-
   CiscoAsr 920-24tz-m Version-
   CiscoAsr 920-4sz-a Version-
   CiscoAsr 920-4sz-d Version-
   CiscoCloud Services Router 1000v Version-
   CiscoNcs 4201 Version-
   CiscoNcs 4202 Version-
   CiscoNcs 4206 Version-
   CiscoNcs 4216 Version-
   CiscoNetwork Convergence System 520 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
psirt@cisco.com 8.6 3.9 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.