SB2016081101 - Denial of service in Cisco IOS XR Software for Cisco ASR 9001 Aggregation Services Routers



SB2016081101 - Denial of service in Cisco IOS XR Software for Cisco ASR 9001 Aggregation Services Routers

Published: August 11, 2016

Security Bulletin ID SB2016081101
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: CVE-2016-6355)

The vulnerability allows a remote attacker to cause a denial of service attack.

The vulnerability exists due to an error in driver processing functions of Cisco IOS XR Software for Cisco ASR 9001 Aggregation Services Routers. A remote unauthenticated attacker can send specially crafted fragmented IPv4 or IPv6 packets to unicast address of vulnerable device and cause memory leak on the route processor (RP).The packets can be send to arbitrary address of the affected device.

Successful exploitation of this vulnerability will result in denial of service of the vulnerable device.


Remediation

Install update from vendor's website.