VYPR
Unrated severityNVD Advisory· Published Sep 25, 2019· Updated Nov 19, 2024

Cisco IOS XE Software Unified Threat Defense Denial of Service Vulnerability

CVE-2019-12657

Description

Cisco IOS XE UTD denial of service vulnerability allows unauthenticated remote attackers to cause device reload via crafted IPv6 packets.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco IOS XE UTD denial of service vulnerability allows unauthenticated remote attackers to cause device reload via crafted IPv6 packets.

Vulnerability

The vulnerability resides in the Unified Threat Defense (UTD) feature of Cisco IOS XE Software due to improper validation of IPv6 packets. Affected devices have UTD enabled on an interface with IPv6 and are configured with the Snort IPS or URL filtering feature of UTD. [1]

Exploitation

An unauthenticated, remote attacker can exploit this vulnerability by sending specially crafted IPv6 traffic through the affected device. No authentication or user interaction is required. [1]

Impact

Successful exploitation causes the device to reload, leading to a denial of service (DoS) condition. [1]

Mitigation

Cisco has released software updates addressing this vulnerability. Administrators should upgrade to a fixed IOS XE version as specified in the Cisco Security Advisory. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.