#VU24517 Resource management error in Cisco IOS XR - CVE-2019-16018
Published: January 24, 2020
Cisco IOS XR
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect processing of a Border Gateway Protocol (BGP) update message that contains crafted Ethernet VPN (EVPN) attributes. A remote attacker can send specially crafted Mcast Join in RR/ASBR/Retain Route target message, wait for a user on the device to display the EVPN operational routes’ status and cause the BGP process to restart unexpectedly, resulting in a DoS condition.
Remediation
This vulnerability has been patched in the following patches only:
- ncs5500-6.6.1.CSCvr91660
- asr9k-x64-6.6.1.CSCvr91660
- ncs540-6.6.1.CSCvr91660
- ncs6k-6.6.1.CSCvr91660
- asr9k-px-6.6.2.CSCvr91676
- asr9k-x64-6.6.2.CSCvr91676
- xrv9k-6.6.2.CSCvr91676
- ncs560-6.6.25.CSCvr91676
- ncs5500-6.6.25.CSCvr91676
- asr9k-x64-7.0.1.CSCvr91676