PT-2015-4817 · Cisco · Cisco Ios Xr+1

Published

2015-04-15

·

Updated

2017-01-06

·

CVE-2015-0695

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XR versions 4.3.4 through 5.3.0
Description The issue is due to improper handling of bridge-group virtual interface (BVI) traffic when certain features are configured, such as Unicast Reverse Path Forwarding (uRPF), policy-based routing (PBR), quality of service (QoS), or access control lists (ACLs). This allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering the use of a BVI interface for IPv4 packets. Only Typhoon-based line cards on Cisco ASR 9000 Series Aggregation Services Routers are affected.
Recommendations For Cisco IOS XR versions 4.3.4 through 5.3.0, update to a fixed software version to address the vulnerability. As a temporary workaround, consider disabling the features that trigger the vulnerability, such as uRPF, PBR, QoS, or ACLs, until a patch is available. Restrict access to the BVI interface to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0695

Affected Products

Cisco Asr 9000 Series
Cisco Ios Xr