CVE-2018-0241
Summary
| CVE | CVE-2018-0241 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-19 20:29:00 UTC |
| Updated | 2019-10-09 23:31:00 UTC |
| Description | A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IPv4 helper address. An attacker could exploit this vulnerability by sending multiple UDP broadcast packets to the affected device. An exploit could allow the attacker to cause a buffer leak on the affected device, eventually resulting in a DoS condition requiring manual intervention to recover. This vulnerability affects all Cisco IOS XR platforms running 6.3.1, 6.2.3, or earlier releases of Cisco IOS XR Software when at least one IPv4 helper address is configured on an interface of the device. Cisco Bug IDs: CSCvi35625. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Asr 9001 | - | All | All | All |
| Hardware | Cisco | Asr 9001 | - | All | All | All |
| Hardware | Cisco | Asr 9006 | - | All | All | All |
| Hardware | Cisco | Asr 9006 | - | All | All | All |
| Hardware | Cisco | Asr 9010 | - | All | All | All |
| Hardware | Cisco | Asr 9010 | - | All | All | All |
| Hardware | Cisco | Asr 9904 | - | All | All | All |
| Hardware | Cisco | Asr 9904 | - | All | All | All |
| Hardware | Cisco | Asr 9906 | - | All | All | All |
| Hardware | Cisco | Asr 9906 | - | All | All | All |
| Hardware | Cisco | Asr 9910 | - | All | All | All |
| Hardware | Cisco | Asr 9910 | - | All | All | All |
| Hardware | Cisco | Asr 9912 | - | All | All | All |
| Hardware | Cisco | Asr 9912 | - | All | All | All |
| Hardware | Cisco | Asr 9922 | - | All | All | All |
| Hardware | Cisco | Asr 9922 | - | All | All | All |
| Operating System | Cisco | Ios Xr | 4.0.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.1.3.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.2.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.3.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.4.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.0.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.1.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 5.2.5.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.3.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 5.4.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 6.0.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 6.1.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 6.2.3.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.0.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.1.3.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.2.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.3.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 4.4.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.0.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.1.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 5.2.5.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 5.3.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 5.4.3.ce | All | All | All |
| Operating System | Cisco | Ios Xr | 6.0.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 6.1.4.base | All | All | All |
| Operating System | Cisco | Ios Xr | 6.2.3.base | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XR UDP Broadcast Processing Flaw Lets Remote Adjacent Network Users Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco IOS XR Software UDP Broadcast Forwarding Denial of Service Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco IOS XR Software CVE-2018-0241 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.