CVE-2019-1749: Cisco Aggregation Services Router 900 Route Switch Processor 3 OSPFv2 Denial of Service Vulnerability
A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficiently validates ingress traffic on the ASIC used on the RSP3 platform. An attacker could exploit this vulnerability by sending a malformed OSPF version 2 (OSPFv2) message to an affected device. A successful exploit could allow the attacker to cause a reload of the iosd process, triggering a reload of the affected device and resulting in a DoS condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1749?
The severity of CVE-2019-1749 is high, potentially leading to a denial of service condition.
How do I fix CVE-2019-1749?
To fix CVE-2019-1749, update your Cisco IOS XE Software to a version that includes the patch for this vulnerability.
Which Cisco devices are affected by CVE-2019-1749?
CVE-2019-1749 affects the Cisco Aggregation Services Router 900 with Route Switch Processor 3.
Can CVE-2019-1749 be exploited remotely?
No, CVE-2019-1749 can only be exploited by an unauthenticated, adjacent attacker.
What are the potential consequences of CVE-2019-1749?
Exploiting CVE-2019-1749 may cause a device reload, resulting in a service interruption.