QID 317367

Date Published: 2023-10-18

QID 317367: Cisco Internetwork Operating System (IOS) XE Software Denial of Service (DoS) Vulnerability (cisco-sa-ios-xe-l2tp-dos-eB5tuFmV)

A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products:
1000 Series Integrated Services Routers (ISRs)
1100 Integrated Services Routers
4000 Series Integrated Services Routers
Catalyst 8000V Edge Software
Catalyst 8200 Series Edge Platforms
Catalyst 8300 Series Edge Platforms
Catalyst 8500L Edge Platforms
Cloud Services Routers 1000V Series

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ios-xe-l2tp-dos-eB5tuFmV for more information.

    CVEs related to QID 317367

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ios-xe-l2tp-dos-eB5tuFmV URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-l2tp-dos-eB5tuFmV