QID 317308
Date Published: 2023-03-27
QID 317308: Cisco Internetwork Operating System (IOS) XE Software Virtual Fragmentation Reassembly Denial of Service (DoS) Vulnerability (cisco-sa-ipv4-vfr-dos-CXxtFacb)
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Affected Releases
1000 Series Integrated Services Routers
4000 Series Integrated Services Routers
Catalyst 8000V Edge Software Routers
Catalyst 8200 Series Edge Platforms
Catalyst 8300 Series Edge Platforms
Catalyst 8500L Series Edge Platforms
Cloud Services Router 1000V Series
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-ipv4-vfr-dos-CXxtFacb for more information.
- cisco-sa-ipv4-vfr-dos-CXxtFacb -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipv4-vfr-dos-CXxtFacb
CVEs related to QID 317308
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ipv4-vfr-dos-CXxtFacb |
|