PT-2023-5643 · Cisco · Cisco Ios Xe
CVE-2023-20187
·
Publicado
2023-09-27
·
Atualizado
2024-01-25
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (affected versions not specified)
Description
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the handling of IPv6 multicast packets to minimize the risk of exploitation.
Restrict access to the mLRE feature to minimize the risk of exploitation.
Avoid sending specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packets through the affected device until the issue is resolved.
DoS
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Ios Xe