Denial of Service Vulnerability in Cisco Virtualized Packet Core Software
CVE-2017-6678
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 26 June 2017
Summary
A vulnerability exists in the ingress UDP packet processing functionality of Cisco's Virtualized Packet Core-Distributed Instance Software, impacting versions 19.2 through 21.0. This issue stems from inadequate handling of user-supplied data, allowing unauthenticated remote attackers to exploit the vulnerability by sending specifically crafted UDP packets to the network addresses of control function instances. A successful attack can cause both instances to reload, resulting in a denial of service condition that disconnects all subscribers and affects the overall functionality of the system. The vulnerability is exclusively exploitable via IPv4 traffic.
Affected Version(s)
Cisco Virtualized Packet Core-Distributed Instance Cisco Virtualized Packet Core-Distributed Instance
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved