← Back

CVE-2019-1749

nvd nist
Published: Mar 28, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 4.0
Source: NVD

Description

A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficiently validates ingress traffic on the ASIC used on the RSP3 platform. An attacker could exploit this vulnerability by sending a malformed OSPF version 2 (OSPFv2) message to an affected device. A successful exploit could allow the attacker to cause a reload of the iosd process, triggering a reload of the affected device and resulting in a DoS condition.

Affected (48)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.5.1
Version 16.5.2
Version 16.5.3
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.6.4
Version 16.7.1
Version 16.7.2
Version 16.8.1
Version 16.8.1b
Version 16.8.1c
Version 3.13.6as
Version 3.16.0as
Version 3.16.1as
Version 3.16.2as
Version 3.16.3as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5s
Version 3.16.6bs
Version 3.16.6s
Version 3.16.7bs
Version 3.16.7s
Version 3.16.8s
Version 3.17.0s
Version 3.17.1s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1bsp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3s
Version 3.18.3sp
Version 3.18.4s
Version 3.18.4sp

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.