CVE-2017-3861

HIGH

Cisco IOS <15.6 & Cisco IOS XE <3.18 - Buffer Overflow/DoS

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Cisco IOS Software and Cisco IOS XE Software support EnergyWise for IPv4 communication. Only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger these vulnerabilities. IPv6 packets cannot be used to trigger these vulnerabilities. Cisco Bug ID CSCut47751.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038313
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97935

Scores

CVSS v3 8.6
EPSS 0.0278
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (50)
cisco/ios 12.2\(33\)sxi4
cisco/ios 12.2\(33\)sxi4a
cisco/ios 12.2\(33\)sxi5
cisco/ios 12.2\(33\)sxi6
cisco/ios 12.2\(33\)sxi7
cisco/ios 12.2\(33\)sxi8
cisco/ios 12.2\(33\)sxi8a
cisco/ios 12.2\(33\)sxi9
cisco/ios 12.2\(33\)sxi10
cisco/ios 12.2\(33\)sxi11
... and 40 more
Published Apr 20, 2017
Tracked Since Feb 18, 2026