Executive brief
A vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. The flaw is due to improper validation of packet data sent to TCP port 4786, which can trigger a reload of affected client switches.
Affected products
- Cisco IOS Software
- Cisco IOS XE Software
Timeline
- 2018-03-28: disclosed: Initial Cisco advisory publication date
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog