SB2017050304 - Denial of service in Cisco IOS XR
Published: May 3, 2017
Security Bulletin ID
SB2017050304
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Denial of service (CVE-ID: CVE-2017-3876)
The vulnerability alows a remote attacker to cause DoS condition on the target device.The weakness exists due to improper handling of gRPC requests in the Event Management Service daemon (emsd) of Cisco IOS XR routers. A remote attacker can send unauthenticated gRPC requests to the affected device and crash the device in such a manner that manual intervention is required to recover.
Successful exploitation of the vulnerability may result in denial of service.
Remediation
Install update from vendor's website.