CVE-2018-0472
A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to improper processing of malformed IPsec Authentication Header (AH) or Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by sending malformed IPsec packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.
- CVSS 3.0
- 8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 16.22% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/ios xe
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/105418Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041735Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041737Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-094-04
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-ipsecVendor Advisory
- http://www.securityfocus.com/bid/105418Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041735Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041737Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-094-04
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-ipsecVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.