CVE-2018-0209
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.
Published:Mar 8, 2018
Last Modified:Dec 2, 2024
EPS:Mar 8, 2018
EPSS Score:0.0067
CVSS Score:7.7
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Sf500-24
Cisco
Sf500-24
Vendor
Cisco
Product
Sf500-24mp
Cisco
Sf500-24mp
Vendor
Cisco
Product
Sf500-24p
Cisco
Sf500-24p
Vendor
Cisco
Product
Sf500-48
Cisco
Sf500-48
Vendor
Cisco
Product
Sf500-48mp
Cisco
Sf500-48mp
Vendor
Cisco
Product
Sf500-48p
Cisco
Sf500-48p
Vendor
Cisco
Product
Sg500-28
Cisco
Sg500-28
Vendor
Cisco
Product
Sg500-28mpp
Cisco
Sg500-28mpp
Vendor
Cisco
Product
Sg500-28p
Cisco
Sg500-28p
Vendor
Cisco
Product
Sg500-52
Cisco
Sg500-52
Vendor
Cisco
Product
Sg500-52mp
Cisco
Sg500-52mp
Vendor
Cisco
Product
Sg500-52p
Cisco
Sg500-52p
Vendor
Cisco
Product
Sg500x-24
Cisco
Sg500x-24
Vendor
Cisco
Product
Sg500x-24mpp
Cisco
Sg500x-24mpp
Vendor
Cisco
Product
Sg500x-24p
Cisco
Sg500x-24p
Vendor
Cisco
Product
Sg500x-48
Cisco
Sg500x-48
Vendor
Cisco
Product
Sg500x-48mp
Cisco
Sg500x-48mp
Vendor
Cisco
Product
Sg500x-48p
Cisco
Sg500x-48p
Vendor
Cisco
Product
Sg500xg-8f8t
Cisco
Sg500xg-8f8t
Vendor
Cisco
Product
Small Business 500 Series Stackable Managed Switches Firmware
Cisco
Small Business 500 Series Stackable Managed Switches Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
