PT-2018-3860 · Cisco · Cisco Ios Xe

CVE-2018-0315

·

Publicado

2018-06-06

·

Atualizado

2023-01-24

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1
Description A vulnerability in the authentication, authorization, and accounting (AAA) security services could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect memory operations that the affected software performs when the software parses a username during login authentication. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device or cause the affected device to reload, resulting in a DoS condition.
Recommendations For Cisco IOS XE Software versions Fuji 16.7.1 through Fuji 16.8.1, update to a newer version that addresses this vulnerability. As a temporary workaround, consider restricting access to the AAA security services until a patch is available. Avoid using the username parameter in the affected login authentication process until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00712
CVE-2018-0315

Produtos afetados

Cisco Ios Xe