QID 317358

Date Published: 2023-09-21

QID 317358: Cisco Internetwork Operating System (IOS) XR Software Denial of Service (DoS) Vulnerability (cisco-sa-ios-xr-cfm-3pWN8MKt)

A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Versions
Prior to version 7.5.4
7.6 prior to version 7.6.3
7.7 prior to version 7.7.21
7.8 prior to version 7.8.2
7.9 prior to version 7.9.1

QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ios-xr-cfm-3pWN8MKt for more information.

    CVEs related to QID 317358

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ios-xr-cfm-3pWN8MKt URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKt