Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wx7-j39g-4p6g

Опубликовано: 12 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. 

This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. 

This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

EPSS

Процентиль: 21%
0.00067
Низкий

7.4 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.4
nvd
11 месяцев назад

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
fstec
больше 1 года назад

Уязвимость операционной системы Cisco IOS XR, связанная с неограниченным распределением ресурсов, позволяющая вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00067
Низкий

7.4 High

CVSS3

Дефекты

CWE-770