CVE-2017-6627

HIGH KEV

Cisco Ios - Improper Resource Release

Title source: rule

Description

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

Scores

CVSS v3 7.5
EPSS 0.1018
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CISA KEV 2022-03-03
VulnCheck KEV 2022-03-03
InTheWild.io 2022-03-03
ENISA EUVD EUVD-2017-15681
CWE
CWE-399 CWE-404
Status published
Products (50)
cisco/ios 15.1\(2\)gc
cisco/ios 15.1\(2\)gc1
cisco/ios 15.1\(2\)gc2
cisco/ios 15.1\(4\)gc
cisco/ios 15.1\(4\)gc1
cisco/ios 15.1\(4\)gc2
cisco/ios 15.2\(1\)gc
cisco/ios 15.2\(1\)gc1
cisco/ios 15.2\(1\)gc2
cisco/ios 15.2\(2\)gc
... and 40 more
Published Sep 07, 2017
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026