CVE-2018-15373

Description

A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory handling by the affected software when the software processes high rates of Cisco Discovery Protocol packets that are sent to a device. An attacker could exploit this vulnerability by sending a high rate of Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to exhaust memory on the affected device, resulting in a DoS condition.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.252

Associated Vulnerability

VulnerabilityOS Platform
Cisco IOS and IOS XE Software Cisco Discovery Protocol Denial of Service Vulnerability For Cisco IOSNCM
Cisco IOS and IOS XE Software Cisco Discovery Protocol Denial of Service Vulnerability For Cisco IOS XE SoftwareNCM
Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2018-15373)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234