QID 317061

Date Published: 2021-09-28

QID 317061: Cisco Internetwork Operating System (IOS) Unidirectional Link Detection Denial of Service (DoS) Vulnerability (cisco-sa-ios-nxos-xr-udld-dos-W5hGHgtQ)

A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload

Affected Products
Cisco devices if they were running a vulnerable release of the following Cisco software and had the UDLD feature enabled:
IOS Software
IOS XE Software
Also affected the following Cisco products if they were running a vulnerable release of Cisco FXOS or NX-OS Software and had the UDLD feature enabled:
Firepower 4100 Series (CSCvw26130)
Firepower 9300 Security Appliances
Note: No support for FXOS Software hence for Firepower 4100 and Firepower 9330 Security Appliances.

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ios-nxos-xr-udld-dos-W5hGHgtQ for more information.

    CVEs related to QID 317061

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ios-nxos-xr-udld-dos-W5hGHgtQ URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-nxos-xr-udld-dos-W5hGHgtQ