cisco-sa-20200122-ios-xr-dos: Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
A vulnerability in the implementation of the Intermediate System-to-Intermediate System (IS-IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS-IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS-IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS-IS process. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-ios-xr-dos
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20200122-ios-xr-dos?
The severity of cisco-sa-20200122-ios-xr-dos is classified as high due to its potential to cause a denial of service condition.
How do I fix cisco-sa-20200122-ios-xr-dos?
To fix cisco-sa-20200122-ios-xr-dos, update the Cisco IOS XR Software to the latest patched version as recommended in the advisory.
What products are affected by cisco-sa-20200122-ios-xr-dos?
Affected products by cisco-sa-20200122-ios-xr-dos include Cisco NCS560, NCS540, NCS5500, and ASR9K routers running specific vulnerable versions.
Who can exploit cisco-sa-20200122-ios-xr-dos?
Cisco-sa-20200122-ios-xr-dos can be exploited by an authenticated, remote attacker.
What is the impact of cisco-sa-20200122-ios-xr-dos?
The impact of cisco-sa-20200122-ios-xr-dos is a denial of service condition affecting the IS-IS routing protocol functionality.