#VU34091 Infinite loop in Cisco IOS XR - CVE-2020-3449
Published: August 6, 2020
Cisco IOS XR
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an incorrect calculation of lexicographical order when displaying additional path information within the Border Gateway Protocol (BGP) additional paths feature. A remote attacker can send a specific BGP update from a BGP neighbor peer session of an affected device, consume all available system resources and cause denial of service conditions.