CVE-2018-0369 describes a denial-of-service vulnerability in Cisco StarOS running on virtual platforms, affecting Cisco Virtualized Packet Core and Ultra Packet Core products. Improper handling of fragmented IPv4 packets with options can cause the npusim process to reload, disrupting traffic. This high-severity vulnerability (CVSS 8.6) can be exploited remotely by an unauthenticated attacker with low complexity, leading to a temporary but impactful service disruption. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21.3, < 21.3.15CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.4, < 21.5.7CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.6, < 21.6.4CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.