← back
CVE-2019-1747

Cisco IOS and IOS XE Software Short Message Service Denial of Service Vulnerability

CVSS 8.6 HIGHEPSS 2.4%CWE-20
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 2.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
27 Mar 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of SMS protocol data units (PDUs) that are encoded with a special character set. An attacker could exploit this vulnerability by sending a malicious SMS message to an affected device. A successful exploit could allow the attacker to cause the wireless WAN (WWAN) cellular interface module on an affected device to crash, resulting in a DoS condition that would require manual intervention to restore normal operating conditions.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →