Junglewise Threat Intelligence

CVE-2017-6627: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

CVE-2017-6627 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS XE, Cisco IOS, Cisco IOS XR. Vendors: Cisco.

Executive brief

A vulnerability in the UDP processing code of Cisco IOS and IOS XE allows unauthenticated remote attackers to cause a denial-of-service (DoS) condition. The flaw exists because certain application changes create UDP sockets and leave them idle without closing them; sending UDP packets with a destination port of 0 can wedge the interface queue.

Affected products

  • Cisco IOS 15.1, 15.2, 15.4
  • Cisco IOS XE 3.14 through 3.18

Timeline

  • 2017-09-06: disclosed: Original Cisco advisory date based on URL slug
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats