Vulnerabilities > Cisco > ASR 9904

DATE CVE VULNERABILITY TITLE RISK
2018-01-31 CVE-2018-0136 Unspecified vulnerability in Cisco IOS XR 5.3.4
A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.8
2016-05-25 CVE-2016-1407 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
network
low complexity
cisco CWE-20
5.0
2015-09-20 CVE-2015-6301 Resource Management Errors vulnerability in Cisco products
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.
network
low complexity
cisco CWE-399
5.0
2015-09-18 CVE-2015-6297 Resource Management Errors vulnerability in Cisco IOS XR 5.2.0Base
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
network
low complexity
cisco CWE-399
5.0
2015-07-22 CVE-2015-4284 Improper Input Validation vulnerability in Cisco IOS XR 5.3.0
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
network
low complexity
cisco CWE-20
5.0
2015-06-23 CVE-2015-4205 Resource Management Errors vulnerability in Cisco IOS XR 5.3.1
Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
5.7
2015-04-17 CVE-2015-0695 Resource Management Errors vulnerability in Cisco IOS XR
Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, does not properly handle bridge-group virtual interface (BVI) traffic, which allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering use of a BVI interface for IPv4 packets, aka Bug ID CSCur62957.
network
low complexity
cisco CWE-399
7.8
2015-04-11 CVE-2015-0694 Improper Access Control vulnerability in Cisco products
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
network
low complexity
cisco CWE-284
5.0
2015-03-26 CVE-2015-0672 Resource Management Errors vulnerability in Cisco IOS XR 5.2.2
The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
network
low complexity
cisco CWE-399
5.0
2014-10-05 CVE-2014-3396 Permissions, Privileges, and Access Controls vulnerability in Cisco products
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
network
low complexity
cisco CWE-264
7.5