PT-2023-5643 · Cisco · Cisco Ios Xe
Published
2023-09-27
·
Updated
2024-01-25
·
CVE-2023-20187
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (affected versions not specified)
Description
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the handling of IPv6 multicast packets to minimize the risk of exploitation.
Restrict access to the mLRE feature to minimize the risk of exploitation.
Avoid sending specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packets through the affected device until the issue is resolved.
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe