QID 317284
QID 317284: Cisco Internetwork Operating System (IOS) XR Software Border Gateway Protocol Ethernet VPN Denial of Service (DoS) Vulnerability (cisco-sa-bgpevpn-zWTRtPBb)
A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Affected Products
Cisco devices if they were running Cisco IOS XR Software releases
Prior to 6.8.2
Prior to 7.3.2
Prior to 7.4.2
and had BGP configured with at least one peer that was configured with the address family L2VPN EVPN.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-bgpevpn-zWTRtPBb for more information.
- cisco-sa-bgpevpn-zWTRtPBb -
www.cisco.com/c/en/us/support/docs/csa/cisco-sa-bgpevpn-zWTRtPBb.html
CVEs related to QID 317284
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-bgpevpn-zWTRtPBb |
|