QID 316902
Date Published: 2021-03-30
QID 316902: Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability(cisco-sa-alg-dos-hbBS7SZE)
A vulnerability in the DNS application layer gateway (ALG) functionality
used by Network Address Translation (NAT) in Cisco IOS XE Software
could allow an unauthenticated, remote attacker to cause an affected device to reload.
Affected Products
Cisco devices if they are running a vulnerable release of Cisco IOS XE Software that is
configured for NAT operation and has the DNS ALG feature enabled. The DNS ALG feature is enabled
as soon as NAT is configured on the device.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition on an affected device.
Customers are advised to refer to cisco-sa-alg-dos-hbBS7SZE for more information.
- cisco-sa-alg-dos-hbBS7SZE -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-alg-dos-hbBS7SZE
CVEs related to QID 316902
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-alg-dos-hbBS7SZE |
|