CVE-2017-6599: Medium severity Cisco IOS XR vulnerability
A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco IOS XR Software with gRPC enabled. More Information: CSCvb14433. Known Affected Releases: 6.1.1.BASE 6.2.1.BASE. Known Fixed Releases: 6.2.1.22i.MGBL 6.1.22.9i.MGBL 6.1.21.12i.MGBL 6.1.2.13i.MGBL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOS XR Software (gRPC/EMSD)to a version that resolves this vulnerability.Fixed in 6.2.1.22i.MGBLPatch CSCvb14433 - Upgrade
Upgrade
Cisco IOS XR Software (gRPC/EMSD)to a version that resolves this vulnerability.Fixed in 6.1.22.9i.MGBLPatch CSCvb14433 - Upgrade
Upgrade
Cisco IOS XR Software (gRPC/EMSD)to a version that resolves this vulnerability.Fixed in 6.1.21.12i.MGBLPatch CSCvb14433 - Upgrade
Upgrade
Cisco IOS XR Software (gRPC/EMSD)to a version that resolves this vulnerability.Fixed in 6.1.2.13i.MGBLPatch CSCvb14433
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6599?
CVE-2017-6599 has a severity rating that indicates it could lead to a denial of service condition.
How do I fix CVE-2017-6599?
To mitigate CVE-2017-6599, it is recommended to upgrade Cisco IOS XR Software to a version that does not contain the vulnerability.
What impact does CVE-2017-6599 have on Cisco IOS XR Software?
CVE-2017-6599 can cause the Event Management Service daemon to crash, resulting in service interruption.
Who is affected by CVE-2017-6599?
CVE-2017-6599 affects users running Cisco IOS XR versions 6.1.1 and 6.2.1.
Can CVE-2017-6599 be exploited remotely?
Yes, CVE-2017-6599 can be exploited by an unauthenticated, remote attacker.