cisco-sa-20200122-ios-xr-dos
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
High · Updated · Cisco
1 product with CSAF evidence
A vulnerability in the implementation of the Intermediate System-to-Intermediate System (IS-IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS-IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS-IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS-IS process. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
| Product | CVE |
|---|---|
| Cisco IOS XR Software | CVE-2019-16027 |