Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wx7-j39g-4p6g

Опубликовано: 12 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. 

This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. 

This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

EPSS

Процентиль: 14%
0.00227
Низкий

7.4 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.4
nvd
больше 1 года назад

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
fstec
почти 2 года назад

Уязвимость операционной системы Cisco IOS XR, связанная с неограниченным распределением ресурсов, позволяющая вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00227
Низкий

7.4 High

CVSS3

Дефекты

CWE-770