← Back

CVE-2019-12653

nvd nist
Published: Sep 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establishing a TCP session and then sending a malicious TCP segment via IPv4 to an affected device. This cannot be exploited via IPv6, as the Raw Socket Transport feature does not support IPv6 as a network layer protocol.

Affected (2)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
2 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 16.10.1
Version 16.9
Running on/withPlatform Versions
Cisco
Asr 902
All versions
Cisco
Asr 902u
All versions
Cisco
Asr 903
All versions
Cisco
Asr 907
All versions
Cisco
Asr 914
All versions

Timeline

No history available yet.