Executive Summary

Summary
TitleCisco IOS XR Software BGP MPLS-Based EVPN Denial of Service Vulnerability
Informations
Namecisco-sa-20190515-iosxr-evpn-dosFirst vendor Publication2019-05-15
VendorCiscoLast vendor Modification2019-05-15
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:A/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score6.1Attack RangeAdjacent network
Cvss Impact Score6.9Attack ComplexityLow
Cvss Expoit Score6.5AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.

The vulnerability is due to a logic error that occurs when the affected software processes specific EVPN routing information. An attacker could exploit this vulnerability by injecting malicious traffic patterns into the targeted EVPN network.

A successful exploit could result in a crash of the l2vpn_mgr process on Provider Edge (PE) device members of the same EVPN instance (EVI). On each of the affected devices, a crash could lead to system instability and the inability to process or forward traffic through the device, resulting in a DoS condition that would require manual intervention to restore normal operating conditions.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-iosxr-evpn-dos ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-iosxr-evpn-dos"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJc3Dq6XBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczCSAP+gM27igNlscosG2Jt3Vk6kWL6wVm XRWrtnCO9gkuPAGjT3hQYNEVbuRd5rHDfVuPAw38cAORgUjPh6brX1/MbbjYnYhq esZRU+dx/lJsIWDtbhf9XlndSsUGNWW2M5LV/noH5tU2/MyEBOR0/bMOPKePJjX5 t1VBdDIn8IhQowzkdTN2bhqVVt/LWNUswVfs5FAzalYjl9s/7xMKmALPvnvbCIA6 9pZz/CLqkpOAxBzvNdZajS3/p6P2K0my60JgrmOXwhQWpWVjXXu/XLdwq+ZPIjX7 aowrcDwwokwq0+ExKhB8eXRDLjT8gRZbRCfA8kJy3/K9+BWnO4Ss56teUIbGMRcM DPaB3sMpZbXbRCSpMRJJpJCRvW6txnJP2YIo6Ewh5uju7wh7jaicAktPqnHp3PGM MRnk3rt5O/l1ZJCz4p+Ih6nOz2801tDuPEtez3YD93mau2w6MxnJ7GxPNEt2KnKK Qww880rI6+Sle40ZeJWjBoGRWQ+8sDJnAJvBGQFj8LZLaUJPrjCtzXYPm0hjaDly OW66J/HZ4HKl9C8Zb1/H/KmXjY+6yuHYfFtxXm3KOhVxt7wbeGj7BoUXkpt93eaX nUvhnizFxJhnwpEgiYQBKBDyY1VyC7hQAdKVVaO+TIqLO1R4RyqpoOSJyV6BtssL DMdsmBNdJYAYQq8C =zgqx END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

%idName
100 %CWE-754Improper Check for Unusual or Exceptional Conditions

CPE : Common Platform Enumeration

TypeDescriptionCount
Os4

Alert History

If you want to see full details history, please login or register.
0
1
2
DateInformations
2019-05-17 21:22:01
  • Multiple Updates
2019-05-16 09:21:38
  • Multiple Updates
2019-05-15 21:18:35
  • First insertion