| Vulnerability Name: | CVE-2018-0472 (CCN-150446) | ||||||||||||
| Assigned: | 2017-11-27 | ||||||||||||
| Published: | 2018-09-26 | ||||||||||||
| Updated: | 2019-04-15 | ||||||||||||
| Summary: | A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to improper processing of malformed IPsec Authentication Header (AH) or Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by sending malformed IPsec packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device. | ||||||||||||
| CVSS v3 Severity: | 8.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) 7.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-0472 Source: BID Type: Third Party Advisory, VDB Entry 105418 Source: CCN Type: BID-105418 Multiple Cisco Products CVE-2018-0472 Denial Of Service Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041735 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041737 Source: XF Type: UNKNOWN cisco-cve20180472-dos(150446) Source: MISC Type: UNKNOWN https://ics-cert.us-cert.gov/advisories/ICSA-19-094-04 Source: CCN Type: Cisco Security Advisory cisco-sa-20180926-ipsec Cisco IOS XE Software and Cisco ASA 5500-X Series Adaptive Security Appliance IPsec Denial of Service Vulnerability Source: CISCO Type: Vendor Advisory 20180926 Cisco IOS XE Software and Cisco ASA 5500-X Series Adaptive Security Appliance IPsec Denial of Service Vulnerability | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||