PT-2019-1978 · Cisco · Cisco Ios Xr 64-Bit+2

Publicado

2019-04-17

·

Atualizado

2019-10-09

·

CVE-2019-1710

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XR 64-bit Software versions prior to 6.5.3 Cisco IOS XR 64-bit Software versions prior to 7.0.1
Description A vulnerability in the sysadmin virtual machine on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The issue is due to incorrect isolation of the secondary management interface from internal sysadmin applications. An attacker could exploit this by connecting to one of the listening internal applications, potentially resulting in unstable conditions, including denial of service and remote unauthenticated access to the device.
Recommendations For versions prior to 6.5.3, update to Cisco IOS XR 64-bit Software Release 6.5.3. For versions prior to 7.0.1, update to Cisco IOS XR 64-bit Software Release 7.0.1. As a temporary workaround, consider restricting access to the secondary management interface to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01671
CVE-2019-1710

Produtos afetados

Cisco Asr 9000 Series Aggregation Services Routers
Cisco Ios Xr 64-Bit
Cisco Ios Xr