{"containers":{"cna":{"affected":[{"product":"Cisco IOS Software","vendor":"Cisco","versions":[{"status":"affected","version":"15.x"}]}],"datePublic":"2019-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to cause either an interface queue wedge or a device reload. The vulnerability is due to the incorrect handling of certain IPv4 packet streams that are sent through the device. An attacker could exploit this vulnerability by sending specific IPv4 packet streams through the device. An exploit could allow the attacker to either cause an interface queue wedge or a device reload, resulting in a denial of service (DoS) condition."}],"exploits":[{"lang":"en","value":"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."}],"metrics":[{"cvssV3_0":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2019-03-28T09:06:08.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"20190327 Cisco IOS Software NAT64 Denial of Service Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nat64"},{"name":"107601","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/107601"}],"source":{"advisory":"cisco-sa-20190327-nat64","defect":[["CSCvk61580"]],"discovery":"INTERNAL"},"title":"Cisco IOS Software NAT64 Denial of Service Vulnerability","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","DATE_PUBLIC":"2019-03-27T16:00:00-0700","ID":"CVE-2019-1751","STATE":"PUBLIC","TITLE":"Cisco IOS Software NAT64 Denial of Service Vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cisco IOS Software","version":{"version_data":[{"version_affected":"=","version_value":"15.x"}]}}]},"vendor_name":"Cisco"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to cause either an interface queue wedge or a device reload. The vulnerability is due to the incorrect handling of certain IPv4 packet streams that are sent through the device. An attacker could exploit this vulnerability by sending specific IPv4 packet streams through the device. An exploit could allow the attacker to either cause an interface queue wedge or a device reload, resulting in a denial of service (DoS) condition."}]},"exploit":[{"lang":"en","value":"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."}],"impact":{"cvss":{"baseScore":"8.6","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20"}]}]},"references":{"reference_data":[{"name":"20190327 Cisco IOS Software NAT64 Denial of Service Vulnerability","refsource":"CISCO","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nat64"},{"name":"107601","refsource":"BID","url":"http://www.securityfocus.com/bid/107601"}]},"source":{"advisory":"cisco-sa-20190327-nat64","defect":[["CSCvk61580"]],"discovery":"INTERNAL"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T18:28:42.306Z"},"title":"CVE Program Container","references":[{"name":"20190327 Cisco IOS Software NAT64 Denial of Service Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-nat64"},{"name":"107601","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/107601"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-11-19T17:25:00.595910Z","id":"CVE-2019-1751","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-19T19:13:10.677Z"}}]},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2019-1751","datePublished":"2019-03-28T00:00:16.397Z","dateReserved":"2018-12-06T00:00:00.000Z","dateUpdated":"2024-11-19T19:13:10.677Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}