cisco-sa-20180131-ipv6

Cisco Aggregation Services Router 9000 Series IPv6 Fragment Header Denial of Service Vulnerability

High · Updated · Cisco

2 products with CSAF evidence

A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect handling of IPv6 packets with a fragment header extension. An attacker could exploit this vulnerability by sending IPv6 packets designed to trigger the issue either to or through the Trident-based line card. A successful exploit could allow the attacker to trigger a reload of Trident-based line cards, resulting in a DoS during the period of time the line card takes to restart. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.