CVE-2019-1840 describes a denial-of-service vulnerability in Cisco Prime Network Registrar's DHCPv6 input packet processor, affecting versions prior to 8.3(7) and 9.1(2). An unauthenticated, remote attacker can exploit this by sending malformed DHCPv6 packets, causing the server to restart. This vulnerability is contingent on the presence of custom extensions that attempt to modify packet details before sanitization. While rated High by CVSS (7.5), its practical severity is lowered to Medium due to this specific prerequisite. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.3.7CPE matchmatch criteria | cpe:2.3:a:cisco:prime_network_registrar:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:prime_network_registrar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.