Executive Summary

Summary
Title Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers MPLS OAM Denial of Service Vulnerability
Informations
Name cisco-sa-20190515-iosxr-mpls-dos First vendor Publication 2019-05-15
Vendor Cisco Last vendor Modification 2019-05-15
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.

The vulnerability is due to the incorrect handling of certain MPLS OAM packets. An attacker could exploit this vulnerability by sending malicious MPLS OAM packets to an affected device. A successful exploit could allow the attacker to cause the lspv_server process to crash. The crash could lead to system instability and the inability to process or forward traffic though the device, resulting in a DoS condition that require manual intervention to restore normal operating conditions.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-asr9k-mpls-dos ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-asr9k-mpls-dos"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJc3Dq4XBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfcz+qAQALoIjtcmK2cQp8BX9iPDAaN9V3O7 sXhezKXFwBwRzQJdLltxRO95x5AAO1f61RR/uC2QmiI70U9R/7H+5O8EnbDzjoef P/qZ1ZGaP0aQ7rDia7B9To7ri84EsM5QcI9otcfUazxnqTC0xVG2Bo50xtDbeQpF qr/oKtX2b53fvTp87OxZKgqVQCN8rUIMZrpvL61ZVAQevjmY8E8chZRWw+L1QXlu H5CTfK06bLn8+LMPOxxAILFIfIo4G+SecshnYlW1Tj/It8qtaxgJOWPHQe8Aessm 0jMREcUTdqYkO7nAIHD6fhPSNPrugM6Lvpslly3Aqe0Xrhpqxca5UpgegzP5xf4C aUDWTe4Rhe1wodAgfP7u1EyVlhegAg2C+HqOTJkOVmtSv4PEKW2RtJ1P3hcIxldG HnuwBRIuMItqunUzfBL7439XfXqxlEtTqWWputclnzP+NSrYp7RRwxB3feXIfzGc MjF26M+66mSsT12YgRUVV/8YbjWaxbClc9Hq2l/oGkULyNkgbdp8AIK/cCO1s26n vaElZQS2rd0hCG+7DS1TTGuPAPqkHDI9N/j1sYF7XOWe4Cqll3+i4ShEt5sq44v4 LIugF72N/Xom2Tx+FtvK5ZdYhMw2zvaRX+yLh9wUUZtttNmAumxvDhIwKWyj0h50 qlPjd+XcCmRBJVi0 =m6Ok END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2019-05-15 21:18:33
  • First insertion