QID 317156

Date Published: 2022-05-09

QID 317156: Cisco Internetwork Operating System (IOS) XE Software AppNav-XE Denial of Service (DoS) Vulnerability (cisco-sa-appnav-xe-dos-j5MXTR4)

A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated,
remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.

Affected Products
Cisco products if they are running a vulnerable release of Cisco IOS XE Software and have the AppNav-XE feature enabled:
1000 Series Integrated Services Routers
4000 Series Integrated Services Routers
ASR 1001-X Routers
ASR 1002-X Routers
Catalyst 8300 Series Routers
Catalyst 8500 Series Routers
Catalyst 8000V Edge Software
Cloud Services Router 1000V Series
Note: No support for Catalyst 8300,8500Series Routers and 8000V Edge Router.

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause the device to reload.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-appnav-xe-dos-j5MXTR4 for more information.

    CVEs related to QID 317156

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-appnav-xe-dos-j5MXTR4 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appnav-xe-dos-j5MXTR4