cisco-sa-20200122-ios-xr-routes: Cisco IOS XR Software BGP EVPN Operational Routes Denial of Service Vulnerability
A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains crafted EVPN attributes. An attacker could indirectly exploit the vulnerability by sending BGP EVPN update messages with a specific, malformed attribute to an affected system and waiting for a user on the device to display the EVPN operational routes’ status. If successful, the attacker could cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-ios-xr-routes
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20200122-ios-xr-routes?
The severity of cisco-sa-20200122-ios-xr-routes is classified as high due to the potential for a denial of service condition.
How do I fix cisco-sa-20200122-ios-xr-routes?
To fix cisco-sa-20200122-ios-xr-routes, update your Cisco IOS XR Software to the recommended version as per the advisory.
What devices are affected by cisco-sa-20200122-ios-xr-routes?
Devices affected by cisco-sa-20200122-ios-xr-routes include various Cisco IOS XR platforms such as NCS5500, NCS560, and ASR9K.
What kind of attack does cisco-sa-20200122-ios-xr-routes enable?
cisco-sa-20200122-ios-xr-routes enables an unauthenticated remote attacker to execute a denial of service attack.
Is user authentication required to exploit the vulnerability in cisco-sa-20200122-ios-xr-routes?
No, user authentication is not required to exploit the vulnerability described in cisco-sa-20200122-ios-xr-routes.