| Vulnerability Name: | CVE-2017-3803 (CCN-120944) | ||||||||||||
| Assigned: | 2016-12-21 | ||||||||||||
| Published: | 2017-01-18 | ||||||||||||
| Updated: | 2019-10-03 | ||||||||||||
| Summary: | A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition. More Information: CSCva72252. Known Affected Releases: 15.2(2)E3 15.2(4)E1. Known Fixed Releases: 15.2(2)E6 15.2(4)E3 15.2(5)E1 15.2(5.3.28i)E1 15.2(6.0.49i)E 3.9(1)E. | ||||||||||||
| CVSS v3 Severity: | 4.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L) 4.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-772 | ||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-3803 Source: BID Type: Third Party Advisory, VDB Entry 95632 Source: CCN Type: BID-95632 Cisco Catalyst 2960 and 3750 Series Switches CVE-2017-3803 Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1037657 Source: XF Type: UNKNOWN cisco-cve20173803-dos(120944) Source: CCN Type: Cisco Security Advisory cisco-sa-20170118-catalyst Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability Source: CONFIRM Type: Mitigation, Vendor Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-catalyst | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||