PT-2017-2361 · Cisco · Cisco Ios Xr

Publicado

2017-05-03

·

Atualizado

2019-10-03

·

CVE-2017-3876

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XR versions 6.1.1
Description The issue is related to errors in resource management in the Event Management Service of Cisco IOS XR routers. It can be exploited by a remote, unauthenticated attacker to cause a denial of service condition on the affected device. The vulnerability is caused by improper handling of gRPC requests. An attacker can exploit this by repeatedly sending unauthenticated gRPC requests to the device. A successful exploit could allow the attacker to crash the device, requiring manual intervention for recovery.
Recommendations For Cisco IOS XR version 6.1.1, update to a newer version that includes the fix for this issue. As a temporary workaround, consider disabling the gRPC service on the affected device until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01561
CVE-2017-3876

Produtos afetados

Cisco Ios Xr