← back
CVE-2018-0170

CVE-2018-0170

EPSS 2.7%CWE-416
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 2.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Mar 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been freed. An attacker could exploit this vulnerability by sending crafted, malformed IP packets to an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvb86327.
Affected products
n/a · Cisco IOS XE

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →