First published: Fri Apr 15 2022(Updated: )
A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handling of malformed packets that are received on the Lightspeed-Plus line cards. An attacker could exploit this vulnerability by sending a crafted IPv4 or IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the Lightspeed-Plus line card to reset, resulting in a denial of service (DoS) condition for any traffic that traverses that line card.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XR | ||
Cisco Asr 9902 | ||
Cisco Asr 9903 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20714 is a vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers.
CVE-2022-20714 could allow an unauthenticated, remote attacker to cause the line card to reset.
The severity of CVE-2022-20714 is high with a severity value of 8.6.
To fix CVE-2022-20714, Cisco has released software updates that address the vulnerability. Please refer to the referenced Cisco Security Advisory for more information.
You can find more information about CVE-2022-20714 in the referenced Cisco Security Advisory.