First published: Wed Jan 22 2020(Updated: )
A vulnerability in the implementation of the Intermediate System-to-Intermediate System (IS-IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS-IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS-IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS-IS process. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-ios-xr-dos
Credit: This vulnerability was found during the resolution a Cisco TAC support case
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XR | =6.6.25<NCS560=6.6.25<NCS540=6.6.25<NCS5500=6.6.2<XRV9K=6.6.2<ASR9K-X64=6.6.2<ASR9K-PX=6.6.1<NCS5500=6.5.3<XRV9K=6.5.3<ASR9K-PX=6.5.3<NCS5K=6.5.3<NCS540=6.5.3<NCS5500=6.5.3<ASR9K-X64=6.5.2<NCS5500=6.5.2<NCS5K=6.5.2<ASR9K-X64=6.5.2<ASR9K-PX=6.4.2<XRV9K=6.4.2<NCS6K>=6.4.2<=6.4.2<NCS5K=6.4.2<ASR9K-X64=6.4.2<ASR9K-PX=6.3.3<NCS6K=6.3.3<NCS5500=6.3.3<NCS540=6.3.3<NCS5K=6.3.3<ASR9K-PX=6.3.3<ASR9K-X64=6.3.2<ASR9K-X64=6.3.2<ASR9K-PX=6.3.15<NCS5500=6.2.3<NCS6K=6.2.3<XRV9K>=6.2.3<=6.2.3<NCS5500=6.2.3<ASR9K-X64=6.2.3<ASR9K-PX=6.2.3<NCS5K=6.2.25<NCS6K=6.2.25<NCS5K=6.2.2<NCS6K=6.2.2<ASR9K-PX=6.1.4<XRV9K=6.1.4<NCS5K>=6.1.4<=6.1.4<NCS5500=6.1.4<ASR9K-PX=6.1.3<NCS5500=6.1.3<NCS5K=6.1.3<ASR9K-PX=6.1.2<ASR9K-PX=5.2.5<NCS6K=4.3.2<XR12000 | NCS560 NCS540 NCS5500 XRV9K ASR9K-X64 ASR9K-PX NCS5500 XRV9K ASR9K-PX NCS5K NCS540 NCS5500 ASR9K-X64 NCS5500 NCS5K ASR9K-X64 ASR9K-PX XRV9K NCS6K NCS5K ASR9K-X64 ASR9K-PX NCS6K NCS5500 NCS540 NCS5K ASR9K-PX ASR9K-X64 ASR9K-X64 ASR9K-PX NCS5500 NCS6K XRV9K NCS5500 ASR9K-X64 ASR9K-PX NCS5K NCS6K NCS5K NCS6K ASR9K-PX XRV9K NCS5K NCS5500 ASR9K-PX NCS5500 NCS5K ASR9K-PX ASR9K-PX NCS6K XR12000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.