PT-2019-1978 · Cisco · Cisco Ios Xr 64-Bit+2

Published

2019-04-17

·

Updated

2019-10-09

·

CVE-2019-1710

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XR 64-bit Software versions prior to 6.5.3 Cisco IOS XR 64-bit Software versions prior to 7.0.1
Description A vulnerability in the sysadmin virtual machine on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The issue is due to incorrect isolation of the secondary management interface from internal sysadmin applications. An attacker could exploit this by connecting to one of the listening internal applications, potentially resulting in unstable conditions, including denial of service and remote unauthenticated access to the device.
Recommendations For versions prior to 6.5.3, update to Cisco IOS XR 64-bit Software Release 6.5.3. For versions prior to 7.0.1, update to Cisco IOS XR 64-bit Software Release 7.0.1. As a temporary workaround, consider restricting access to the secondary management interface to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01671
CVE-2019-1710

Affected Products

Cisco Asr 9000 Series Aggregation Services Routers
Cisco Ios Xr 64-Bit
Cisco Ios Xr