CVE-2018-0480

Published Oct 5, 2018

Last updated 5 years ago

Overview

Description
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the software. An attacker could exploit this vulnerability by sending frames that trigger the errdisable condition. A successful exploit could allow the attacker to cause the affected device to crash, leading to a DoS condition.
Source
ykramarz@cisco.com
NVD status
Modified

Risk scores

CVSS 3.0

Type
Primary
Base score
6.1
Impact score
4
Exploitability score
1.6
Vector string
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
5.7
Impact score
6.9
Exploitability score
5.5
Vector string
AV:A/AC:M/Au:N/C:N/I:N/A:C

Weaknesses

nvd@nist.gov
CWE-362
ykramarz@cisco.com
CWE-362

Social media

Hype score
Not currently trending

Configurations