PT-2015-4762 · Cisco · Cisco Ios Xr+2
Published
2015-02-20
·
Updated
2015-11-27
·
CVE-2015-0618
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR versions 5.0.1 through 5.2.1 on Network Convergence System (NCS) 6000 devices
Cisco IOS XR versions 5.1.3 through 5.1.4 on Carrier Routing System X (CRS-X) devices
Description
The issue allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers. This is due to improper processing of malformed IPv6 packets carrying extension headers. An attacker could exploit this by sending a malformed IPv6 packet, carrying extension headers, through an affected Cisco IOS XR device line card, allowing the attacker to cause a reload of the line card on the affected Cisco IOS XR device.
Recommendations
For Cisco IOS XR versions 5.0.1 through 5.2.1 on Network Convergence System (NCS) 6000 devices, update to a fixed software version.
For Cisco IOS XR versions 5.1.3 through 5.1.4 on Carrier Routing System X (CRS-X) devices, update to a fixed software version.
As a temporary workaround, consider restricting the processing of IPv6 packets with extension headers until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Carrier Routing System X
Cisco Ios Xr
Network Convergence System (Ncs) 6000