QID 317232
Date Published: 2022-10-04
QID 317232: Cisco Internetwork Operating System (IOS) XE Software Internet Protocol (IPv6) Virtual Private Network (VPN) over MPLS Denial of Service (DoS) Vulnerability (cisco-sa-iosxe-6vpe-dos-tJBtf5Zv)
A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
Affected Products:
This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XE Software and have both 6VPE and ZBFW features enabled.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
Note: This QID does not checks for the workaround hence kept as practice
A successful exploit could allow the attacker to reload the device, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-iosxe-6vpe-dos-tJBtf5Zv for more information.
- cisco-sa-iosxe-6vpe-dos-tJBtf5Zv -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-6vpe-dos-tJBtf5Zv
CVEs related to QID 317232
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxe-6vpe-dos-tJBtf5Zv |
|