CVE-2018-0421
Last modified
CVE-2018-0421 is a vulnerability of currently unknown severity. A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. EPSS estimates a 3.48% chance of exploitation in the next 30 days.
Description
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Prime Access Registrar | >= 7.3, < 7.3.0.4 |
| Cisco | Prime Access Registrar | >= 8.0, < 8.0.1.1 |
| Cisco | Prime Access Registrar Jumpstart | >= 7.3, < 7.3.0.4 |
| Cisco | Prime Access Registrar Jumpstart | >= 8.0, < 8.0.1.1 |
References
- http://www.securityfocus.com/bid/105282Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041684Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105282Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041684Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0421?
How severe is CVE-2018-0421?
How do I fix CVE-2018-0421?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0415A vulnerability in the implementation of Extensible Authenti…
- CVE-2018-0416A vulnerability in the web-based interface of Cisco Wireless…5.3
- CVE-2018-0417A vulnerability in TACACS authentication with Cisco Wireless…7.8
- CVE-2018-0418A vulnerability in the Local Packet Transport Services (LPTS…8.6
- CVE-2018-0419A vulnerability in certain attachment detection mechanisms o…
- CVE-2018-0420A vulnerability in the web-based interface of Cisco Wireless…6.5
- CVE-2018-0422A vulnerability in the folder permissions of Cisco Webex Mee…
- CVE-2018-0423A vulnerability in the web-based management interface of the…
- CVE-2018-0424A vulnerability in the web-based management interface of the…8.8
- CVE-2018-0425A vulnerability in the web-based management interface of the…
- CVE-2018-0426A vulnerability in the web-based management interface of the…
- CVE-2018-0427A vulnerability in the CronJob scheduler API of Cisco Digita…8.8
Are you affected by CVE-2018-0421?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
