CVE-2019-1739: Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1739?
The severity of CVE-2019-1739 is rated as high due to the potential for unauthenticated remote attackers to cause device reloads.
How do I fix CVE-2019-1739?
To fix CVE-2019-1739, upgrade to the applicable software versions released by Cisco which address the vulnerability.
Which Cisco IOS versions are affected by CVE-2019-1739?
CVE-2019-1739 affects various versions of Cisco IOS and Cisco IOS XE Software, specifically versions 15.1 and newer.
What types of attacks exploit CVE-2019-1739?
CVE-2019-1739 can be exploited through crafted DNS packets that trigger a parsing issue leading to a device reload.
Are there any workarounds for CVE-2019-1739?
Workarounds for CVE-2019-1739 include disabling the Network-Based Application Recognition feature on affected devices.