Executive brief
A vulnerability in the UDP processing code of Cisco IOS and IOS XE allows unauthenticated remote attackers to cause a denial-of-service (DoS) condition. The flaw exists because certain application changes create UDP sockets and leave them idle without closing them; sending UDP packets with a destination port of 0 can wedge the interface queue.
Affected products
- Cisco IOS 15.1, 15.2, 15.4
- Cisco IOS XE 3.14 through 3.18
Timeline
- 2017-09-06: disclosed: Original Cisco advisory date based on URL slug
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog