cisco-sa-20170927-ike: Cisco IOS and IOS XE Software Internet Key Exchange Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
On software releases that support it, configure the crypto ikev2 limit queue sa-init command; Cisco bug CSCvc12306 identifies support for this mitigation.
Cisco IOS Software and Cisco IOS XE Software IKEv2 crypto ikev2 limit queue sa-init = enabled
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20170927-ike?
The severity of cisco-sa-20170927-ike is considered high due to the potential for remote attackers to impact system resources.
How do I fix cisco-sa-20170927-ike?
To fix cisco-sa-20170927-ike, you should apply the relevant software updates or patches provided by Cisco for your affected IOS or IOS XE versions.
What types of devices are affected by cisco-sa-20170927-ike?
cisco-sa-20170927-ike affects devices running Cisco IOS Software and Cisco IOS XE Software.
What potential impacts arise from cisco-sa-20170927-ike?
The potential impacts of cisco-sa-20170927-ike include high CPU utilization, traceback messages, and possible device reloads.
Is authentication required for the attack in cisco-sa-20170927-ike?
No, the attack described in cisco-sa-20170927-ike can be executed by an unauthenticated remote attacker.