8.6
CVE-2019-15989
- EPSS 2.5%
- Veröffentlicht 26.01.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:52
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains a specific BGP attribute. An attacker could exploit this vulnerability by sending BGP update messages that include a specific, malformed attribute to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer or would need to be injected by the attacker into the victim’s BGP network on an existing, valid TCP connection to a BGP peer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xr Version6.6.1
Cisco ≫ Asr 9000v Version- HwPlatformx64
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Ncs 540 Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Ncs 6000 Version-
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Ncs 540 Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Ncs 6000 Version-
Cisco ≫ Ios Xr Version6.6.2
Cisco ≫ Asr 9000v Version-
Cisco ≫ Asr 9000v Version- HwPlatformx64
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version-
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Crs Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Xrv 9000 Version-
Cisco ≫ Asr 9000v Version- HwPlatformx64
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version-
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Crs Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Xrv 9000 Version-
Cisco ≫ Ios Xr Version7.0.1
Cisco ≫ Asr 9000v Version- HwPlatformx64
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Ncs 1001 Version-
Cisco ≫ Ncs 1002 Version-
Cisco ≫ Ncs 1004 Version-
Cisco ≫ Ncs 5001 Version-
Cisco ≫ Ncs 5002 Version-
Cisco ≫ Ncs 540 Version-
Cisco ≫ Ncs 540l Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Ncs 560 Version-
Cisco ≫ Ncs 6000 Version-
Cisco ≫ Xrv 9000 Version-
Cisco ≫ Asr 9001 Version- HwPlatformx64
Cisco ≫ Asr 9006 Version- HwPlatformx64
Cisco ≫ Asr 9010 Version- HwPlatformx64
Cisco ≫ Asr 9901 Version- HwPlatformx64
Cisco ≫ Asr 9904 Version- HwPlatformx64
Cisco ≫ Asr 9906 Version- HwPlatformx64
Cisco ≫ Asr 9910 Version- HwPlatformx64
Cisco ≫ Asr 9912 Version- HwPlatformx64
Cisco ≫ Asr 9922 Version- HwPlatformx64
Cisco ≫ Ncs 1001 Version-
Cisco ≫ Ncs 1002 Version-
Cisco ≫ Ncs 1004 Version-
Cisco ≫ Ncs 5001 Version-
Cisco ≫ Ncs 5002 Version-
Cisco ≫ Ncs 540 Version-
Cisco ≫ Ncs 540l Version-
Cisco ≫ Ncs 5501 Version-
Cisco ≫ Ncs 5501-se Version-
Cisco ≫ Ncs 5502 Version-
Cisco ≫ Ncs 5502-se Version-
Cisco ≫ Ncs 5508 Version-
Cisco ≫ Ncs 5516 Version-
Cisco ≫ Ncs 560 Version-
Cisco ≫ Ncs 6000 Version-
Cisco ≫ Xrv 9000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.5% | 0.847 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
psirt@cisco.com | 8.6 | 3.9 | 4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.