← Back

CVE-2019-16018

nvd nist
Published: Jan 26, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains crafted EVPN attributes. An attacker could indirectly exploit the vulnerability by sending BGP EVPN update messages with a specific, malformed attribute to an affected system and waiting for a user on the device to display the EVPN operational routes’ status. If successful, the attacker could cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.

Affected (4)

Products: Cisco: Ios Xr
1 product
Ios Xr
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.6.1
Configuration B
1 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Version 6.6.2
Running on/withPlatform Versions
Cisco
Asr 9000v
All versions
Cisco
Asr 9001
All versions
Cisco
Asr 9006
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9901
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9906
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions
Cisco
Crs
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.6.25
Configuration D
1 vulnerable · 26 platform
Vulnerable SoftwareAffected Versions
Version 7.0.1
Running on/withPlatform Versions
Cisco
Asr 9000v
All versions
Cisco
Asr 9001
All versions
Cisco
Asr 9006
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9901
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9906
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions
Cisco
Ncs 1001
All versions
Cisco
Ncs 1002
All versions
Cisco
Ncs 1004
All versions
Cisco
Ncs 5001
All versions
Cisco
Ncs 5002
All versions
Cisco
Ncs 540
All versions
Cisco
Ncs 540l
All versions
Cisco
Ncs 5501
All versions
Cisco
Ncs 5501 Se
All versions
Cisco
Ncs 5502
All versions
Cisco
Ncs 5502 Se
All versions
Cisco
Ncs 5508
All versions
Cisco
Ncs 5516
All versions
Cisco
Ncs 560
All versions
Cisco
Ncs 6000
All versions
Cisco
Xrv 9000
All versions

Timeline

No history available yet.