Executive brief
A vulnerability in certain Cisco Catalyst switches could allow an attacker on the same local network to cause a memory leak. Over time, this leak can exhaust system resources, leading to a partial service outage where the switch can no longer process certain types of network traffic. This impacts the reliability of the local network and may require a manual reboot of the hardware to restore full functionality.
Technical details
A memory leak vulnerability (CWE-772) exists in the software forwarding queue of Cisco IOS for Catalyst 2960X and 3750X switches. The root cause is the improper processing of IPv6 Neighbor Discovery (ND) packets, where the system fails to free allocated memory after processing. An unauthenticated attacker on an adjacent network can exploit this by sending a stream of IPv6 ND packets to the device. This results in a gradual exhaustion of memory and CPU resources, eventually causing a partial Denial of Service (DoS) for features requiring software forwarding. Recovery requires a device reload, and fixed releases include 15.2(2)E6, 15.2(4)E3, and 15.2(5)E1.
Affected products
- Cisco IOS 15.2(2)E3, 15.2(4)E1
Timeline
- 2017-01-18: advisory: Initial public release by Cisco
- 2017-01-26: disclosed: NVD publication date
- 2017-03-03: other: Advisory updated to version 1.1