CVE-2017-3859 is a format string vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers running Cisco IOS XE Software versions 3.13 through 3.18. An unauthenticated, remote attacker can exploit this by sending a specially crafted DHCP packet to cause a device reload, leading to a denial of service (DoS) condition. This vulnerability has a CVSSv3 score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.13.4sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.4s:*:*:*:*:*:*:* | ||
3.13.5asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.5as:*:*:*:*:*:*:* | ||
3.13.5sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.5s:*:*:*:*:*:*:* | ||
3.13.6asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.6as:*:*:*:*:*:*:* | ||
3.13.6sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.6s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.