cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S: Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability
A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751.This vulnerability is due to a lack of proper error validation of ingress XML packets. An
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S?
The cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S vulnerability is classified as a denial of service (DoS) risk, which can significantly impact system availability.
How do I fix cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S?
To remediate cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S, update the Cisco IOS XR Software to the latest version that addresses this vulnerability.
Which devices are affected by cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S?
Cisco IOS XR Software, particularly versions deployed on Cisco IOS XRv 9000, are susceptible to the cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S vulnerability.
What type of attack is possible with cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S?
The cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S vulnerability allows an unauthenticated, remote attacker to cause a denial of service on the XML TCP listen port 38751.
Is authentication required to exploit cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S?
No, exploitation of the cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S vulnerability does not require authentication, making it particularly dangerous.