QID 317427
Date Published: 2024-04-04
QID 317427: Cisco Internetwork Operating System (IOS) XR Software for ASR 9000 Series Aggregation Services Routers PPPoE Denial of Service (DoS) Vulnerability (cisco-sa-iosxr-pppma-JKWFgneW)
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service (DoS) condition.
Affected Products
Cisco IOS XR Software releases prior to 7.9.21
Cisco IOS XR Software releases From 7.10 prior to 7.10.1
Cisco IOS XR Software releases From 7.11 prior to 7.11.1
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to crash the ppp_ma process, resulting in a DoS condition for PPPoE traffic across the router.
Customers are advised to refer to cisco-sa-iosxr-pppma-JKWFgneW for more information.
- cisco-sa-iosxr-pppma-JKWFgneW -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-pppma-JKWFgneW
CVEs related to QID 317427
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxr-pppma-JKWFgneW |
|