PT-2016-1017 · Cisco · Cisco Ios Xr

Publicado

2016-01-04

·

Atualizado

2016-12-07

·

CVE-2015-6432

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS XR versions 4.2.0 through 5.3.2
Description The issue is related to the handling of Open Shortest Path First (OSPF) Link State Advertisement (LSA) updates, specifically with the number of Path Computation Elements (PCEs) configured for an OSPF LSA opaque area update. This could allow a remote attacker to cause a denial of service (DoS) condition by sending a crafted OSPF LSA update. The exploitation of this issue can lead to the OSPF process restarting when the crafted update is received.
Recommendations For Cisco IOS XR versions 4.2.0 through 5.3.2, update to a fixed software version to address this issue. As a temporary workaround, consider restricting the number of OSPF Path Computation Elements (PCEs) for OSPF LSA opaque area updates to minimize the risk of exploitation.

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00080
CVE-2015-6432

Produtos afetados

Cisco Ios Xr