Cisco ASR 9000 Series Aggregation Services Routers Vulnerable to Denial of Service Attack via PPPoE Termination
CVE-2024-20327

7.4HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 March 2024

Summary

A vulnerability exists within the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software used in Cisco ASR 9000 Series Aggregation Services Routers. This flaw arises from the improper processing of malformed PPPoE packets on routers utilizing Broadband Network Gateway (BNG) functionality with PPPoE termination. An adjacent, unauthenticated attacker could exploit this vulnerability by sending specially crafted PPPoE packets to an interface on the line card that is not configured for PPPoE termination. Successful exploitation would lead to the crashing of the ppp_ma process, resulting in a denial of service (DoS) condition affecting PPPoE traffic processing across the router.

Affected Version(s)

Cisco IOS XR Software 5.2.0

Cisco IOS XR Software 5.2.2

Cisco IOS XR Software 5.2.4

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.