CVE-2019-12653: Cisco IOS XE Software Raw Socket Transport Denial of Service Vulnerability
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establishing a TCP session and then sending a malicious TCP segment via IPv4 to an affected device. This cannot be exploited via IPv6, as the Raw Socket Transport feature does not support IPv6 as a network layer protocol.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12653?
CVE-2019-12653 is a vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software that could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.
What is the severity of CVE-2019-12653?
The severity of CVE-2019-12653 is high with a CVSS score of 7.5.
How does CVE-2019-12653 affect Cisco IOS XE Software?
CVE-2019-12653 affects Cisco IOS XE Software versions 16.9 and 16.10.1.
How can an attacker exploit CVE-2019-12653?
An unauthenticated, remote attacker can exploit CVE-2019-12653 by sending malicious Raw Socket Transport payloads to the affected device.
Is there a fix available for CVE-2019-12653?
Yes, Cisco has released a security advisory with information on how to mitigate the vulnerability. Please refer to the Cisco Security Advisory for more details.