QID 317032
Date Published: 2021-09-09
QID 317032: Cisco Internetwork Operating System (IOS) XR Software for ASR 9000 Series Routers Denial of Service (DoS) Vulnerability (cisco-sa-npspin-QYpwdhFD)
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers
could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot.
Affected Products
Cisco IOS XR Software when all the following conditions apply:
i. The Cisco IOS XR Software release is Release 6.4.0 or later but earlier than a first fixed release.
ii. The software is running on Cisco ASR 9000 Series Aggregation Services Routers.
iii. These routers have either a Typhoon or Tomahawk Ethernet line card installed.
Vulnerable releases:
From 6.4.0 Prior to 6.6.3
From 6.7 Prior to 6.7.1
From 7.0 Prior to 7.0.2
From 7.1 Prior to 7.1.1
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to cause the affected line card to reboot.
Customers are advised to refer to cisco-sa-npspin-QYpwdhFD for more information.
- cisco-sa-npspin-QYpwdhFD -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-npspin-QYpwdhFD
CVEs related to QID 317032
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-npspin-QYpwdhFD |
|