CVE-2018-15373
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory handling by the affected software when the software processes high rates of Cisco Discovery Protocol packets that are sent to a device. An attacker could exploit this vulnerability by sending a high rate of Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to exhaust memory on the affected device, resulting in a DoS condition.
- CVSS 3.0
- 7.4 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399, CWE-770
- Affected
- cisco/ios · cisco/ios xe
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/105413Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-094-03
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-cdp-dosVendor Advisory
- http://www.securityfocus.com/bid/105413Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-094-03
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-cdp-dosVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.