QID 317045
Date Published: 2021-09-23
QID 317045: Cisco Internetwork Operating System (IOS) and IOS XE Software TrustSec CLI Parser Denial of Service (DoS) Vulnerability (cisco-sa-trustsec-dos-7fuXDR2)
A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software
could allow an authenticated, remote attacker to cause an affected device to reload.
Affected Products
Cisco devices if they are running a vulnerable release of Cisco IOS or IOS XE Software, have TrustSec capabilities, and have the web UI enabled.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Customers are advised to refer to cisco-sa-trustsec-dos-7fuXDR2 for more information.
- cisco-sa-trustsec-dos-7fuXDR2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-trustsec-dos-7fuXDR2
CVEs related to QID 317045
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-trustsec-dos-7fuXDR2 |
|