QID 317222
Date Published: 2022-09-29
QID 317222: Cisco Internetwork Operating System (IOS) XR Software Broadband Network Gateway PPP over Ethernet Denial of Service (DoS) Vulnerability (cisco-sa-iosxr-bng-Gmg5Gxt)
A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the PPPoE process to continually crash.
Affected Products
ASR 9000 Series Aggregation Services Routers
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command Along with it checks if Cisco Discovery Protocol is enabled.
A successful exploit could allow the attacker to cause the PPPoE process to continually restart, resulting in a denial of service condition (DoS).
Solution
Customers are advised to refer to cisco-sa-iosxr-bng-Gmg5Gxt for more information.
Vendor References
- cisco-sa-iosxr-bng-Gmg5Gxt -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bng-Gmg5Gxt
CVEs related to QID 317222
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxr-bng-Gmg5Gxt |
|