← Back

CVE-2019-16019

nvd nist
Published: Sep 23, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.

Affected (4)

Products: Cisco: Ios Xr
1 product
Ios Xr
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.6.1
Configuration B
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Version 6.6.2
Running on/withPlatform Versions
Cisco
Asr 9000
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions
Cisco
Carrier Routing System
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.6.25
Configuration D
1 vulnerable · 18 platform
Vulnerable SoftwareAffected Versions
Version 7.0.1
Running on/withPlatform Versions
Cisco
Asr 9000
All versions
Cisco
Asr 9010
All versions
Cisco
Asr 9904
All versions
Cisco
Asr 9910
All versions
Cisco
Asr 9912
All versions
Cisco
Asr 9922
All versions
Cisco
Ios Xrv 9000
All versions
Cisco
Ncs 1001
All versions
Cisco
Ncs 1002
All versions
Cisco
Ncs 1004
All versions
Cisco
Ncs 5001
All versions
Cisco
Ncs 5002
All versions
Cisco
Ncs 5011
All versions
Cisco
Ncs 540
All versions
Cisco
Ncs 540l
All versions
Cisco
Ncs 5500
All versions
Cisco
Ncs 560
All versions
Cisco
Ncs 6000
All versions

Related CWEs

Timeline

No history available yet.