Denial of Service Vulnerability in Cisco Industrial Ethernet 2000 Series Switches
CVE-2017-3812

6.8MEDIUM

What is CVE-2017-3812?

A flaw in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches allows unauthenticated remote attackers to exploit a system memory leak. This condition can lead to a denial of service (DoS), impacting the availability of the affected systems. The issue affects specific firmware versions and requires immediate attention to mitigate the associated risks.

Affected Version(s)

Cisco Industrial Ethernet 2000 Switches 15.2(5.4.32i)E2 Cisco Industrial Ethernet 2000 Switches 15.2(5.4.32i)E2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.