PT-2019-1978 · Cisco · Cisco Ios Xr 64-Bit+2
Published
2019-04-17
·
Updated
2019-10-09
·
CVE-2019-1710
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR 64-bit Software versions prior to 6.5.3
Cisco IOS XR 64-bit Software versions prior to 7.0.1
Description
A vulnerability in the sysadmin virtual machine on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The issue is due to incorrect isolation of the secondary management interface from internal sysadmin applications. An attacker could exploit this by connecting to one of the listening internal applications, potentially resulting in unstable conditions, including denial of service and remote unauthenticated access to the device.
Recommendations
For versions prior to 6.5.3, update to Cisco IOS XR 64-bit Software Release 6.5.3.
For versions prior to 7.0.1, update to Cisco IOS XR 64-bit Software Release 7.0.1.
As a temporary workaround, consider restricting access to the secondary management interface to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asr 9000 Series Aggregation Services Routers
Cisco Ios Xr 64-Bit
Cisco Ios Xr