First published: Wed Dec 14 2016(Updated: )
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process. More Information: CSCvb38398. Known Affected Releases: 20.2.3 20.2.3.65026. Known Fixed Releases: 21.1.M0.65431 21.1.PP0.65733 21.1.R0.65467 21.1.R0.65496 21.1.VC0.65434 21.1.VC0.65489 21.2.A0.65437.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASR 5000 Series Aggregation Services Routers | =20.0.2.3.65026 | |
Cisco ASR 5000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9203 is considered a high severity vulnerability due to its potential to allow remote attackers to reload the ipsecmgr process without authentication.
To fix CVE-2016-9203, upgrade to a fixed release of the Cisco ASR 5000 Series Software, such as version 21.1.M or later.
CVE-2016-9203 affects Cisco ASR 5000 Series Software versions 20.2.3 and 20.2.3.65026.
CVE-2016-9203 can cause a denial of service by reloading the ipsecmgr process, leading to temporary network disruptions.
There is no documented workaround for CVE-2016-9203, so it is recommended to apply the appropriate software patch.