ZeroHour

CVE-2017-6627

KEVmass

Unauthenticated UDP Queue-Wedge DoS in Cisco IOS and IOS XE Software

CISA: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2017-6627 is a denial-of-service flaw in the UDP packet processing code of Cisco IOS and IOS XE, caused by application changes that create UDP sockets and leave them idle without closing them. An unauthenticated, remote attacker can trigger it by sending UDP packets with a destination port of 0 to an affected device, causing packets to be held in the interface input queue; once roughly 250 packets accumulate, the queue wedges and the device stops forwarding traffic on that interface until it is cleared or reloaded. A successful attack affects availability only, with no confidentiality or integrity impact (CVSS 3.1: 7.5 High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Any organization running the affected IOS 15.1, 15.2, or 15.4 trains or IOS XE 3.14 through 3.18 is exposed, particularly where the device accepts UDP traffic from untrusted networks or the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation in the wild (ransomware use unknown); no public proof-of-concept is known, and EPSS estimates a 6.0% chance of exploitation in the next 30 days (93rd percentile).

What to do: Inventory routers and switches running IOS 15.1, 15.2, or 15.4 and IOS XE 3.14–3.18, and upgrade to fixed releases per Cisco's advisory (bug IDs CSCup10024, CSCva55744, CSCva95506), as required by the CISA KEV catalog. As an interim mitigation, restrict or filter unsolicited UDP traffic destined to the device itself (for example via infrastructure ACLs) and monitor interface input queues for wedges; a wedged queue may require clearing the interface or reloading the device to restore service.

Affected
Cisco IOS15.1, 15.2, 15.4
Cisco IOS XE3.14 through 3.18
Estimated exposure
masshundreds of thousands of internet-exposed Cisco IOS/IOS XE devices, with an overall installed base in the millions — Cisco IOS/IOS XE is among the most widely deployed network operating systems on routers and switches in enterprise, service provider, and SMB networks, and public internet-wide scans (e.g., Shodan/Censys) consistently show on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-399, CWE-404
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.