CVE-2017-3856 is a denial-of-service vulnerability in the web user interface of Cisco IOS XE versions 3.1 through 3.17, affecting devices with the web UI enabled. This vulnerability, rated 7.5 HIGH on CVSS, allows an unauthenticated, remote attacker to cause a device reload by sending a high volume of requests, due to insufficient resource handling. While the attack requires access to the management interface, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.0s:*:*:*:*:*:*:* | ||
3.1.0sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.0sg:*:*:*:*:*:*:* | ||
3.1.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.1s:*:*:*:*:*:*:* | ||
3.1.1sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.1sg:*:*:*:*:*:*:* | ||
3.1.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.2s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.