CVE-2017-6627
KEVmassUnauthenticated UDP Queue-Wedge DoS in Cisco IOS and IOS XE Software
CISA: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
CVE-2017-6627 is a denial-of-service flaw in the UDP packet processing code of Cisco IOS and IOS XE, caused by application changes that create UDP sockets and leave them idle without closing them. An unauthenticated, remote attacker can trigger it by sending UDP packets with a destination port of 0 to an affected device, causing packets to be held in the interface input queue; once roughly 250 packets accumulate, the queue wedges and the device stops forwarding traffic on that interface until it is cleared or reloaded. A successful attack affects availability only, with no confidentiality or integrity impact (CVSS 3.1: 7.5 High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Any organization running the affected IOS 15.1, 15.2, or 15.4 trains or IOS XE 3.14 through 3.18 is exposed, particularly where the device accepts UDP traffic from untrusted networks or the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation in the wild (ransomware use unknown); no public proof-of-concept is known, and EPSS estimates a 6.0% chance of exploitation in the next 30 days (93rd percentile).
What to do: Inventory routers and switches running IOS 15.1, 15.2, or 15.4 and IOS XE 3.14–3.18, and upgrade to fixed releases per Cisco's advisory (bug IDs CSCup10024, CSCva55744, CSCva95506), as required by the CISA KEV catalog. As an interim mitigation, restrict or filter unsolicited UDP traffic destined to the device itself (for example via infrastructure ACLs) and monitor interface input queues for wedges; a wedged queue may require clearing the interface or reloading the device to restore service.
| Cisco IOS | 15.1, 15.2, 15.4 |
| Cisco IOS XE | 3.14 through 3.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-399, CWE-404
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.