6.1
CVSSv2

CVE-2018-0471

Published: 05/10/2018 Updated: 07/12/2020
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 7.4 | Impact Score: 4 | Exploitability Score: 2.8
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent malicious user to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain CDP packets. An attacker could exploit this vulnerability by sending certain CDP packets to an affected device. A successful exploit could cause an affected device to continuously consume memory and eventually result in a memory allocation failure that leads to a crash, triggering a reload of the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 16.6.1

cisco ios xe 16.6.2

Vendor Advisories

A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 1661 and 1662 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition The vulnerability is due to incorrect processing of certain CDP packets An attacker could exploit this vulne ...