Denial of service in Cisco IOS XR - CVE-2017-12355

 

Denial of service in Cisco IOS XR - CVE-2017-12355

Published: November 29, 2017 / Updated: December 1, 2017


Vulnerability identifier: #VU9512
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12355
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to DoS condition on the target system.

The vulnerability exists in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software due to  incomplete LPTS frame validation. A remote attacker can send specially crafted XML requests to the management interface cause one of the LPTS processes to restart unexpectedly.

Successful exploitation of the vulnerability results in denial of service.


Affected software

Cisco IOS XR

How to mitigate CVE-2017-12355

The vulnerability is addressed in the following versions: 6.4.1.17, 6.3.15.1, 6.3.2.14, 6.2.3.2.





External References

Related Security Bulletins