Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
LOW Published: 2018-05-02
Updated: 2020-09-09
Summary
A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system. The vulnerability is due to improper handling of malformed requests processed by the netconf process. An attacker could exploit this vulnerability by sending malicious requests to the affected software. An exploit could allow the attacker to cause the targeted process to restart, resulting in a DoS condition on the affected system. Cisco Bug IDs: CSCvg95792.
Vulnerable Configurations
Part | Description | Count |
OS | Cisco | 3 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | CISCO |
NASL id | CISCO-SA-20180502-IOSXR.NASL |
description | According to its self-reported version, Cisco IOS XR Software is affected by a denial of service (DoS) vulnerability in the netconf interface due to improper handling of malformed requests. An unauthenticated, remote attacker can exploit this, by sending malicious requests to the affected software, in order to cause the targeted process to restart and a DoS condition on the affected system. Please see the included Cisco BIDs and Cisco Security Advisory for more information |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 133265 |
published | 2020-01-28 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/133265 |
title | Cisco IOS XR Software netconf DoS (cisco-sa-20180502-iosxr) |