PT-2020-1383 · Cisco · Cisco Ios Xr

Published

2020-01-22

·

Updated

2021-10-29

·

CVE-2019-16021

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality. These vulnerabilities could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system, potentially causing the BGP process to restart unexpectedly. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers, so the malicious BGP update message would need to come from a configured, valid BGP peer or be injected into the victim's BGP network on an existing, valid TCP connection to a BGP peer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00333
CVE-2019-16021

Affected Products

Cisco Ios Xr