PT-2022-6956 · Cisco · Cisco Ios Xr

Logan Sanderson

·

Published

2022-10-27

·

Updated

2024-01-25

·

CVE-2023-20233

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software (affected versions not specified)
Description The issue is related to the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software. It is caused by incorrect processing of invalid continuity check messages (CCMs), which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending crafted CCMs to an affected device, potentially causing the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-05816
CVE-2023-20233

Affected Products

Cisco Ios Xr