CVE-2017-12211
A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device.
Does this matter?
Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by polling the affected device IPv6 information. An exploit could allow the attacker to trigger high CPU usage or a reload of the device. Known Affected Releases: Denali-16.3.1. Cisco Bug IDs: CSCvb14640.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/ios · cisco/ios xe
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/100648Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039290Third Party Advisory, VDB Entry
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvb14640Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-snmpVendor Advisory
- http://www.securityfocus.com/bid/100648Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039290Third Party Advisory, VDB Entry
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvb14640Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-snmpVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.