CVE-2018-0117 describes a denial-of-service vulnerability in Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software versions N4.0 through N5.5 running Cisco StarOS 19.2 through 21.3. This flaw, due to insufficient handling of user-supplied data, allows an unauthenticated, remote attacker to send malicious traffic to the internal DI network address. A successful exploit causes both control function instances to reload, leading to a complete VPC reload and disconnection of all subscribers. The vulnerability has a CVSSv3 score of 8.6 (High), indicating a critical risk. It is remotely exploitable with low attack complexity, requiring no user interaction or privileges, and results in a high impact on availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.1.v0.66836CPE matchmatch criteria | cpe:2.3:o:cisco:asr_5000_firmware:21.1.v0.66836:*:*:*:*:*:*:* | ||
21.1.v7CPE matchmatch criteria | cpe:2.3:o:cisco:asr_5000_firmware:21.1.v7:*:*:*:*:*:*:* | ||
21.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:asr_5000_firmware:21.3.0:*:*:*:*:*:*:* | ||
21.6.0CPE matchmatch criteria | cpe:2.3:o:cisco:asr_5000_firmware:21.6.0:*:*:*:*:*:*:* | ||
21.1.v0.66836CPE matchmatch criteria | cpe:2.3:o:cisco:asr_5500_firmware:21.1.v0.66836:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.