SB2017050304 - Denial of service in Cisco IOS XR



SB2017050304 - Denial of service in Cisco IOS XR

Published: May 3, 2017

Security Bulletin ID SB2017050304
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Denial of service (CVE-ID: CVE-2017-3876)

The vulnerability alows a remote attacker to cause DoS condition on the target device.

The weakness exists due to improper handling of gRPC requests in the Event Management Service daemon (emsd) of Cisco IOS XR routers. A remote attacker can send unauthenticated gRPC requests to the affected device and crash the device in such a manner that manual intervention is required to recover.

Successful exploitation of the vulnerability may result in denial of service.

Remediation

Install update from vendor's website.