8.6

CVE-2019-1869

A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of this vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoStaros Version >= 21.6 < 21.6.13
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.6b < 21.6b.16
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.7 < 21.7.11
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.8 < 21.8.10
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.9 < 21.9.7
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.10 < 21.10.2
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
CiscoStaros Version >= 21.11 < 21.11.1
   CiscoAsr 5000 Version-
   CiscoAsr 5500 Version-
   CiscoAsr 5700 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.624
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
psirt@cisco.com 8.6 3.9 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.