Vulnslist

find the latest Cisco vulnerabilities

Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability

cisco-sa-20161207-asr1 · Medium · Published · Updated

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process. The vulnerability is due to a race condition in the IKEv2 negotiation logic. An attacker could exploit this vulnerability by sending crafted IKEv2 packets during a negotiation. An exploit could allow the attacker to cause a crash of the ipsecmgr process, which will restart on its own. Only the connection being negotiated will need to re-establish. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-asr1

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-9203
Cisco Bug IDsCSCvb38398
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco ASR 5000 Series Software

Related Products

Product CVE Evidence
Cisco SR 500 Secure Routers CVE-2016-9203 Cisco OpenVuln
Cisco RV Series Routers CVE-2016-9203 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-9203 Cisco OpenVuln
Cisco ASR 5000 Series Software CVE-2016-9203 Cisco OpenVuln