CVE Feed

    Dashboard / CVE / CVE-2017-3859

    CVE-2017-3859

    A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vulnerability when processing a crafted DHCP packet for Zero Touch Provisioning. An attacker could exploit this vulnerability by sending a specially crafted DHCP packet to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco ASR 920 Series Aggregation Services Routers that are running an affected release of Cisco IOS XE Software (3.13 through 3.18) and are listening on the DHCP server port. By default, the devices do not listen on the DHCP server port. Cisco Bug IDs: CSCuy56385.

    Published:Mar 22, 2017
    Last Modified:Apr 20, 2025
    EPS:Mar 22, 2017
    EPSS Score:0.00344
    CVSS Score:7.5

    Affected Products

    Vendor
    Cisco
    Product
    Asr-920-12cz-a
    Vendor
    Cisco
    Product
    Asr-920-12cz-d
    Vendor
    Cisco
    Product
    Asr-920-12sz-im
    Vendor
    Cisco
    Product
    Asr-920-24sz-im
    Vendor
    Cisco
    Product
    Asr-920-24sz-m
    Vendor
    Cisco
    Product
    Asr-920-24tz-m
    Vendor
    Cisco
    Product
    Asr-920-4sz-a
    Vendor
    Cisco
    Product
    Asr-920-4sz-d
    Vendor
    Cisco
    Product
    Ios Xe

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High