Vulnerabilities > CVE-2018-0286 - Improper Handling of Exceptional Conditions vulnerability in Cisco IOS XR 6.3.1/6.3.2/6.5.1

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
cisco
CWE-755
nessus

Summary

A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system. The vulnerability is due to improper handling of malformed requests processed by the netconf process. An attacker could exploit this vulnerability by sending malicious requests to the affected software. An exploit could allow the attacker to cause the targeted process to restart, resulting in a DoS condition on the affected system. Cisco Bug IDs: CSCvg95792.

Vulnerable Configurations

Part Description Count
OS
Cisco
3

Nessus

NASL familyCISCO
NASL idCISCO-SA-20180502-IOSXR.NASL
descriptionAccording to its self-reported version, Cisco IOS XR Software is affected by a denial of service (DoS) vulnerability in the netconf interface due to improper handling of malformed requests. An unauthenticated, remote attacker can exploit this, by sending malicious requests to the affected software, in order to cause the targeted process to restart and a DoS condition on the affected system. Please see the included Cisco BIDs and Cisco Security Advisory for more information
last seen2020-06-01
modified2020-06-02
plugin id133265
published2020-01-28
reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/133265
titleCisco IOS XR Software netconf DoS (cisco-sa-20180502-iosxr)