PT-2016-1470 · Cisco · Gigabit Switch Router (Gsr) 12000+2
Published
2016-03-11
·
Updated
2016-12-03
·
CVE-2016-1361
CVSS v3.1
5.3
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR versions through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices
Cisco IOS (affected versions not specified)
Description
The issue is related to improper input validation for the presence of a Bidirectional Forwarding Detection (BFD) header in a UDP packet. This allows remote attackers to cause a denial of service (line-card restart) via a crafted packet. The vulnerability is due to errors in resource management. An attacker could exploit this by sending a crafted UDP packet with a specific UDP port range to the affected device, causing a partial denial of service condition when a line card unexpectedly restarts.
Recommendations
For Cisco IOS XR versions through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices: Update to a fixed software version.
For Cisco IOS: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the UDP ingress receive function to minimize the risk of exploitation. Avoid using the
BFD header in UDP packets until the issue is resolved.DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xr
Gigabit Switch Router (Gsr) 12000