QID 317425
QID 317425: Cisco IOS XR Software Layer 2 Services Denial of Service (DoS) Vulnerability (cisco-sa-xrl2vpn-jesrU3fc)
A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network processor to reset, resulting in a denial of service (DoS) condition.
Affected Products
Cisco IOS XR Software releases prior to 7.9.2
Cisco IOS XR Software releases From 7.10 prior to 7.10.1
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
Note: This QID does not checks for service policy or access-control filtering mechanism that examines the IP headers
A successful exploit could allow the attacker to cause the ingress interface network processor to reset, resulting in a loss of traffic over the interfaces that are supported by the network processor.
Customers are advised to refer cisco-sa-xrl2vpn-jesrU3fc for more information.
- cisco-sa-xrl2vpn-jesrU3fc -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrl2vpn-jesrU3fc
CVEs related to QID 317425
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-xrl2vpn-jesrU3fc |
|