Executive brief
A buffer overflow vulnerability in the Quality of Service (QoS) subsystem of Cisco IOS and IOS XE Software allows a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service. The flaw exists due to improper bounds checking on packets sent to UDP port 18999.
Affected products
- Cisco IOS Software
- Cisco IOS XE Software
Timeline
- 2018-03-28: advisory: Initial Cisco Security Advisory published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed