CVE-2023-20027: Cisco IOS XE Software Virtual Fragmentation Reassembly Denial of Service Vulnerability
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel interface or on a physical interface that is configured with a maximum transmission unit (MTU) greater than 4,615 bytes. An attacker could exploit this vulnerability by sending fragmented packets through a VFR-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20027?
CVE-2023-20027 has a severity rating that can cause a denial of service (DoS) condition on an affected device.
How do I fix CVE-2023-20027?
To fix CVE-2023-20027, you should update Cisco IOS XE Software to the latest version that has addressed the vulnerability.
What devices are affected by CVE-2023-20027?
CVE-2023-20027 affects multiple versions of Cisco IOS XE Software, specifically from version 3.9.0as to 17.8.1.
Can CVE-2023-20027 be exploited remotely?
Yes, CVE-2023-20027 can be exploited by unauthenticated, remote attackers.
What impact does CVE-2023-20027 have on network services?
CVE-2023-20027 can cause denial of service, impacting the availability of network services on affected devices.