CVE-2018-0421
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.
- CVSS 3.0
- 8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 3.48% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399, CWE-772
- Affected
- cisco/prime access registrar · cisco/prime access registrar jumpstart
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/105282Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041684Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-cpar-dosVendor Advisory
- http://www.securityfocus.com/bid/105282Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041684Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-cpar-dosVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.