Denial of Service Vulnerability in Cisco IOS XE Software's L2TP Feature
CVE-2023-20227
7.5HIGH
Summary
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software allows an unauthenticated remote attacker to trigger a denial of service condition. This issue is due to improper handling of specially crafted L2TP packets. An attacker can exploit this by sending these packets to an affected device, potentially causing it to reload unexpectedly. This results in service disruption as the device becomes temporarily unavailable. The exploit is limited to traffic directed specifically at the affected system.
Affected Version(s)
Cisco IOS XE Software 16.8.1
Cisco IOS XE Software 16.8.1a
Cisco IOS XE Software 16.8.1b
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved