PT-2016-1470 · Cisco · Gigabit Switch Router (Gsr) 12000+2

Published

2016-03-11

·

Updated

2016-12-03

·

CVE-2016-1361

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR versions through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices Cisco IOS (affected versions not specified)
Description The issue is related to improper input validation for the presence of a Bidirectional Forwarding Detection (BFD) header in a UDP packet. This allows remote attackers to cause a denial of service (line-card restart) via a crafted packet. The vulnerability is due to errors in resource management. An attacker could exploit this by sending a crafted UDP packet with a specific UDP port range to the affected device, causing a partial denial of service condition when a line card unexpectedly restarts.
Recommendations For Cisco IOS XR versions through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices: Update to a fixed software version. For Cisco IOS: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the UDP ingress receive function to minimize the risk of exploitation. Avoid using the BFD header in UDP packets until the issue is resolved.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00771
CVE-2016-1361

Affected Products

Cisco Ios
Cisco Ios Xr
Gigabit Switch Router (Gsr) 12000