Denial of Service Vulnerability in Cisco StarOS on Virtual Platforms
CVE-2018-0369

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
16 July 2018

Summary

A vulnerability exists in the reassembly logic for fragmented IPv4 packets in Cisco StarOS, affecting virtual platforms. This issue may allow an unauthenticated remote attacker to exploit the system by sending crafted IPv4 packets. If successfully exploited, the attacker can trigger a reload of the npusim process, which can lead to a denial of service condition. As there are multiple instances of the npusim process managing traffic, an attacker may affect all instances simultaneously, resulting in impacted service availability during the brief restart period. This vulnerability is particularly concerning for organizations using Cisco's virtual packet core solutions.

Affected Version(s)

Cisco StarOS unknown Cisco StarOS unknown

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.