Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20714

Опубликовано: 15 апр. 2022
Источник: nvd
CVSS3: 8.6
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handling of malformed packets that are received on the Lightspeed-Plus line cards. An attacker could exploit this vulnerability by sending a crafted IPv4 or IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the Lightspeed-Plus line card to reset, resulting in a denial of service (DoS) condition for any traffic that traverses that line card.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:ios_xr:-:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:cisco:asr_9902:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9903:-:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01834
Низкий

8.6 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-126
CWE-125

Связанные уязвимости

CVSS3: 8.6
github
почти 4 года назад

A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handling of malformed packets that are received on the Lightspeed-Plus line cards. An attacker could exploit this vulnerability by sending a crafted IPv4 or IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the Lightspeed-Plus line card to reset, resulting in a denial of service (DoS) condition for any traffic that traverses that line card.

CVSS3: 8.6
fstec
почти 4 года назад

Уязвимость службы Lightspeed-Plus операционной системы Cisco IOS XR маршрутизаторов Cisco ASR 9000, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.01834
Низкий

8.6 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-126
CWE-125