Denial of Service Vulnerability in Cisco StarOS on Virtual Platforms
CVE-2018-0369
Summary
A vulnerability exists in the reassembly logic for fragmented IPv4 packets in Cisco StarOS, affecting virtual platforms. This issue may allow an unauthenticated remote attacker to exploit the system by sending crafted IPv4 packets. If successfully exploited, the attacker can trigger a reload of the npusim process, which can lead to a denial of service condition. As there are multiple instances of the npusim process managing traffic, an attacker may affect all instances simultaneously, resulting in impacted service availability during the brief restart period. This vulnerability is particularly concerning for organizations using Cisco's virtual packet core solutions.
Affected Version(s)
Cisco StarOS unknown Cisco StarOS unknown
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved