QID 317047

Date Published: 2021-09-23

QID 317047: Cisco Internetwork Operating System (IOS) XE Software Interface Queue Wedge Denial of Service (DOS) Vulnerability (cisco-sa-quewedge-69BsHUBW)

A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated,
adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition.

Affected Products
Cisco IOS XE Software if it is running on one of the following Cisco products:
1000 Integrated Services Routers (ISRs)
4000 Series ISRs
ASR 1000 Series Aggregation Services Routers
Cloud Services Router (CSR) 1000V Series
Integrated Services Virtual (ISRv) Routers
Note: Potential detection as cannot confirm the platform

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause a queue wedge on the interface, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-quewedge-69BsHUBW for more information.

    CVEs related to QID 317047

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-quewedge-69BsHUBW URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-quewedge-69BsHUBW