Denial of service in Cisco IOS XR - CVE-2017-12355

 

Denial of service in Cisco IOS XR - CVE-2017-12355

Published: November 29, 2017 / Updated: December 1, 2017


Vulnerability identifier: #VU9512
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12355
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco IOS XR

Detailed vulnerability description

The vulnerability allows a remote attacker to DoS condition on the target system.

The vulnerability exists in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software due to  incomplete LPTS frame validation. A remote attacker can send specially crafted XML requests to the management interface cause one of the LPTS processes to restart unexpectedly.

Successful exploitation of the vulnerability results in denial of service.


How to mitigate CVE-2017-12355

The vulnerability is addressed in the following versions: 6.4.1.17, 6.3.15.1, 6.3.2.14, 6.2.3.2.




Sources