CVE-2018-0466

MEDIUM

Cisco IOS and IOS XE - Unauthenticated Denial of Service via OSPFv3 LSA Packet Handling

Title source: llm
STIX 2.1

Description

A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. The vulnerability is due to incorrect handling of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending crafted OSPFv3 Link-State Advertisements (LSA) to an affected device. An exploit could allow the attacker to cause an affected device to reload, leading to a denial of service (DoS) condition.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105403
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041737

Scores

CVSS v3 6.5
EPSS 0.0095
EPSS Percentile 57.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-399
Status published
Products (2)
cisco/ios 16.2.1
cisco/ios_xe 16.2.1
Published Oct 05, 2018
Tracked Since Feb 18, 2026