PT-2023-5643 · Cisco · Cisco Ios Xe

CVE-2023-20187

·

Publicado

2023-09-27

·

Atualizado

2024-01-25

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (affected versions not specified)
Description A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the handling of IPv6 multicast packets to minimize the risk of exploitation. Restrict access to the mLRE feature to minimize the risk of exploitation. Avoid sending specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packets through the affected device until the issue is resolved.

DoS

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06303
CVE-2023-20187

Produtos afetados

Cisco Ios Xe