543
VMScore

CVE-2019-1749

Published: 28/03/2019 Updated: 07/02/2024
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 7.4 | Impact Score: 4 | Exploitability Score: 2.8
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent malicious user to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficiently validates ingress traffic on the ASIC used on the RSP3 platform. An attacker could exploit this vulnerability by sending a malformed OSPF version 2 (OSPFv2) message to an affected device. A successful exploit could allow the malicious user to cause a reload of the iosd process, triggering a reload of the affected device and resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.18.2s

cisco ios xe 3.17.3s

cisco ios xe 3.16.4s

cisco ios xe 3.18.3s

cisco ios xe 3.18.3sp

cisco ios xe 16.6.1

cisco ios xe 3.18.1sp

cisco ios xe 3.17.4s

cisco ios xe 3.16.6s

cisco ios xe 3.16.5s

cisco ios xe 3.18.1bsp

cisco ios xe 3.18.0s

cisco ios xe 3.17.0s

cisco ios xe 3.16.4ds

cisco ios xe 3.17.1s

cisco ios xe 3.18.2sp

cisco ios xe 3.16.1as

cisco ios xe 3.18.1s

cisco ios xe 3.18.0sp

cisco ios xe 3.16.3as

cisco ios xe 3.13.6as

cisco ios xe 3.16.4bs

cisco ios xe 3.16.2as

cisco ios xe 3.16.6bs

cisco ios xe 16.5.1

cisco ios xe 16.6.3

cisco ios xe 16.8.1

cisco ios xe 16.7.1

cisco ios xe 16.6.2

cisco ios xe 3.16.4gs

cisco ios xe 3.16.4cs

cisco ios xe 3.16.4es

cisco ios xe 16.5.2

cisco ios xe 3.16.5as

cisco ios xe 16.8.1b

cisco ios xe 16.7.2

cisco ios xe 16.8.1c

cisco ios xe 3.18.1isp

cisco ios xe 3.18.1gsp

cisco ios xe 3.18.4s

cisco ios xe 3.16.7s

cisco ios xe 3.16.7bs

cisco ios xe 3.18.4sp

cisco ios xe 16.5.3

cisco ios xe 3.18.1hsp

cisco ios xe 16.6.4

cisco ios xe 3.16.8s

cisco ios xe 3.16.0as

Vendor Advisories

A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition The vulnerability exists because the software insuff ...