Input validation error in Cisco Systems, Inc products - CVE-2023-20187
Published: September 29, 2023
Cisco IOS XE
ASR1000-ESP40
ASR1000-ESP100
ASR1000-ESP200
ASR1001-X
ASR1001-HX
ASR1002-X
ASR1002-HX
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Multicast Leaf Recycle Elimination (mLRE) feature. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.