Denial of Service Vulnerability in Cisco IOS XE Software's L2TP Feature
CVE-2023-20227

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
27 September 2023

Summary

A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software allows an unauthenticated remote attacker to trigger a denial of service condition. This issue is due to improper handling of specially crafted L2TP packets. An attacker can exploit this by sending these packets to an affected device, potentially causing it to reload unexpectedly. This results in service disruption as the device becomes temporarily unavailable. The exploit is limited to traffic directed specifically at the affected system.

Affected Version(s)

Cisco IOS XE Software 16.8.1

Cisco IOS XE Software 16.8.1a

Cisco IOS XE Software 16.8.1b

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.