QID 317230

Date Published: 2022-10-06

QID 317230: Cisco Internetwork Operating System (IOS) and Internetwork Operating System (IOS) XE Software Common Industrial Protocol Request Denial of Service (DoS) Vulnerability (cisco-sa-iosxe-cip-dos-9rTbKLt9)

A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.

Affected Products
Cisco products if they are running a vulnerable release of Cisco IOS or Cisco IOS XE Software and have CIP protocol enabled.

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-iosxe-cip-dos-9rTbKLt9 for more information.

    CVEs related to QID 317230

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-iosxe-cip-dos-9rTbKLt9 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-cip-dos-9rTbKLt9