A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to cause an interface on the device to cease forwarding packets. The device may need to be manually reloaded to clear this Interface Forwarding Denial of Service condition. The vulnerability is due to the failure to properly check that the length of a packet to transmit does not exceed the maximum supported length of the network interface card (NIC). An attacker could exploit this vulnerability by sending a crafted IP packet or a series of crafted IP fragments through an interface on the targeted device. A successful exploit could allow the attacker to cause the network interface to cease forwarding packets. This vulnerability could be triggered by either IPv4 or IPv6 network traffic. This vulnerability affects the following Cisco products when they are running the StarOS operating system and a virtual interface card is installed on the device: Aggregation Services Router (ASR) 5700 Series, Virtualized Packet Core-Distributed Instance (VPC-DI) System Software, Virtualized Packet Core-Single Instance (VPC-SI) System Software. Cisco Bug IDs: CSCvf32385.
総合評価: CVE-2018-0239 は中リスク(61.1/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 3.26%、87 パーセンタイル) 推奨対応: 影響資産を整理し、修補計画に組み込んでください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-05-09 | 2.70% | 3.26% | +0.55% |
| 2 | 2025-07-17 | 3.20% | 2.70% | -0.50% |
| 3 | 2025-05-07 | — | 3.20% | — |
EPSS の全履歴 (全 16 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| cisco | staros | 21.0.v0.65819 | cpe:2.3:o:cisco:staros:21.0.v0.65819:*:*:*:*:*:*:* |
| cisco | staros | 21.0.v4 | cpe:2.3:o:cisco:staros:21.0.v4:*:*:*:*:*:*:* |
| cisco | staros | 21.1.v6 | cpe:2.3:o:cisco:staros:21.1.v6:*:*:*:*:*:*:* |
| cisco | staros | 21.3.1 | cpe:2.3:o:cisco:staros:21.3.1:*:*:*:*:*:*:* |
| cisco | staros | 21.4.0 | cpe:2.3:o:cisco:staros:21.4.0:*:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| http://www.securityfocus.com/bid/103923 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1040720 | Third Party Advisory VDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-staros | Vendor Advisory |