← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-0136

A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect handling of IPv6 packets with a fragment header extension. An attacker could exploit this vulnerability by sending IPv6 packets designed to trigger the issue either to or through the Trident-based line card. A successful exploit could allow the attacker to trigger a reload of Trident-based line cards, resulting in a DoS during the period of time the line card takes to restart. This vulnerability affects Cisco Aggregation Services Router (ASR) 9000 Series when the following conditions are met: The router is running Cisco IOS XR Software Release 5.3.4, and the router has installed Trident-based line cards that have IPv6 configured. A software maintenance upgrade (SMU) has been made available that addresses this vulnerability. The fix has also been incorporated into service pack 7 for Cisco IOS XR Software Release 5.3.4. Cisco Bug IDs: CSCvg46800.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:2.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
cisco ios_xr 5.3.4
cisco asr_9001 all
cisco asr_9006 all
cisco asr_9010 all
cisco asr_9904 all
cisco asr_9906 all
cisco asr_9910 all
cisco asr_9912 all
cisco asr_9922 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.688%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2017-11-27T00:00:00
Published2018-01-31T20:00:00
Patch Date2018-01-31
Last Updated2024-12-02T21:24:47

LINK COPIED TO CLIPBOARD