PT-2020-4888 · Cisco · Cisco Network Convergence System (Ncs) 5000 Series Routers+2
Published
2020-11-10
·
Updated
2020-11-24
·
CVE-2020-26070
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers (affected versions not specified)
Cisco Network Convergence System (NCS) 5000 Series Routers (affected versions not specified)
Description:
A vulnerability in the packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource allocation when an affected device processes network traffic in software switching mode. An attacker could exploit this vulnerability by sending specific streams of Layer 2 or Layer 3 protocol data units (PDUs) to an affected device. A successful exploit could cause the affected device to run out of buffer resources, which could make the device unable to process or forward traffic, resulting in a DoS condition. The device would need to be restarted to regain functionality.
Recommendations:
For Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, update to a software version that addresses this vulnerability.
For Cisco Network Convergence System (NCS) 5000 Series Routers, update to a software version that addresses this vulnerability.
As a temporary workaround, consider restarting the device to regain functionality in case of a successful exploit.
At the moment, there is no information about other workarounds that address this vulnerability.
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asr 9000 Series Aggregation Services Routers
Cisco Ios Xr
Cisco Network Convergence System (Ncs) 5000 Series Routers