Cisco IOS XR Software Vulnerability Could Lead to Denial of Service
CVE-2024-20318

7.4HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 March 2024

Summary

A vulnerability exists within Cisco's IOS XR Software that impacts its Layer 2 Ethernet services. This flaw allows an unauthenticated, adjacent attacker to exploit the software by sending specially crafted Ethernet frames to a vulnerable device. The improper handling of these frames may cause the ingress interface network processor to reset, subsequently leading to a denial of service (DoS) condition for the affected device. Repeated attacks could result in multiple resets, overwhelming the line card and causing significant interruptions to traffic flow through the involved interfaces.

Affected Version(s)

Cisco IOS XR Software 6.5.2

Cisco IOS XR Software 6.5.3

Cisco IOS XR Software 6.6.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.