CVE-2018-15373

HIGH

Cisco IOS and IOS XE - Denial of Service via Cisco Discovery Protocol Packet Flood

Title source: llm
STIX 2.1

Description

A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory handling by the affected software when the software processes high rates of Cisco Discovery Protocol packets that are sent to a device. An attacker could exploit this vulnerability by sending a high rate of Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to exhaust memory on the affected device, resulting in a DoS condition.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105413

Scores

CVSS v3 7.4
EPSS 0.0066
EPSS Percentile 46.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-399 CWE-770
Status published
Products (2)
cisco/ios 15.5\(3\)s3.16
cisco/ios_xe 15.5\(3\)s3.16
Published Oct 05, 2018
Tracked Since Feb 18, 2026