QID 317284

QID 317284: Cisco Internetwork Operating System (IOS) XR Software Border Gateway Protocol Ethernet VPN Denial of Service (DoS) Vulnerability (cisco-sa-bgpevpn-zWTRtPBb)

A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

Affected Products
Cisco devices if they were running Cisco IOS XR Software releases Prior to 6.8.2
Prior to 7.3.2
Prior to 7.4.2
and had BGP configured with at least one peer that was configured with the address family L2VPN EVPN.

QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-bgpevpn-zWTRtPBb for more information.

    Vendor References

    CVEs related to QID 317284

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-bgpevpn-zWTRtPBb URL Logo www.cisco.com/c/en/us/support/docs/csa/cisco-sa-bgpevpn-zWTRtPBb.html