QID 317150
Date Published: 2022-04-19
QID 317150: Cisco Internetwork Operating System (IOS) XE Software NETCONF Over SSH Denial of Service (DoS) Vulnerability (cisco-sa-ncossh-dos-ZAkfOdq8)
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device.
Affected Products
Cisco Catalyst 3850 Series Switches
Cisco Catalyst 9200 Series Switches
Cisco Catalyst 9300 Series Switches
Cisco Catalyst 9400 Series Switches
Cisco Catalyst 9500 Series Switches
Cisco Catalyst 9500H Series Switches
Cisco Catalyst 9600 Series Switches
Note: This vulnerability affects Cisco products if they are running a vulnerable release of Cisco IOS XE Software and have the NETCONF over SSH feature enabled.
QID Detection Logic (Authenticated):
The check matches affected versions retrieved via SNMP.
A successful exploit could allow the attacker to exhaust resources, causing the device to reload and resulting in a DoS condition on an affected device.
Customers are advised to refer to cisco-sa-ncossh-dos-ZAkfOdq8 for more information.
- cisco-sa-ncossh-dos-ZAkfOdq8 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ncossh-dos-ZAkfOdq8
CVEs related to QID 317150
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ncossh-dos-ZAkfOdq8 |
|