PT-2023-5643 · Cisco · Cisco Ios Xe

Published

2023-09-27

·

Updated

2024-01-25

·

CVE-2023-20187

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (affected versions not specified)
Description A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the handling of IPv6 multicast packets to minimize the risk of exploitation. Restrict access to the mLRE feature to minimize the risk of exploitation. Avoid sending specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packets through the affected device until the issue is resolved.

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-06303
CVE-2023-20187

Affected Products

Cisco Ios Xe