8.6

CVE-2019-16019

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xr Version6.6.1
   CiscoAsr 9000 Version- HwPlatformx64
   CiscoAsr 9010 Version- HwPlatformx64
   CiscoAsr 9904 Version- HwPlatformx64
   CiscoAsr 9910 Version- HwPlatformx64
   CiscoAsr 9912 Version- HwPlatformx64
   CiscoAsr 9922 Version- HwPlatformx64
   CiscoNcs 540 Version-
   CiscoNcs 5500 Version-
   CiscoNcs 6000 Version-
CiscoIos Xr Version6.6.2
   CiscoAsr 9000 Version- HwPlatform-
   CiscoAsr 9000 Version- HwPlatformx64
   CiscoAsr 9010 Version- HwPlatform-
   CiscoAsr 9010 Version- HwPlatformx64
   CiscoAsr 9904 Version- HwPlatform-
   CiscoAsr 9904 Version- HwPlatformx64
   CiscoAsr 9910 Version- HwPlatform-
   CiscoAsr 9910 Version- HwPlatformx64
   CiscoAsr 9912 Version- HwPlatform-
   CiscoAsr 9912 Version- HwPlatformx64
   CiscoAsr 9922 Version- HwPlatform-
   CiscoAsr 9922 Version- HwPlatformx64
   CiscoCarrier Routing System Version-
   CiscoIos Xrv 9000 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5500 Version-
   CiscoNcs 6000 Version-
CiscoIos Xr Version6.6.25
   CiscoNcs 540 Version-
   CiscoNcs 540l Version-
   CiscoNcs 5500 Version-
   CiscoNcs 560 Version-
CiscoIos Xr Version7.0.1
   CiscoAsr 9000 Version- HwPlatformx64
   CiscoAsr 9010 Version- HwPlatformx64
   CiscoAsr 9904 Version- HwPlatformx64
   CiscoAsr 9910 Version- HwPlatformx64
   CiscoAsr 9912 Version- HwPlatformx64
   CiscoAsr 9922 Version- HwPlatformx64
   CiscoIos Xrv 9000 Version-
   CiscoNcs 1001 Version-
   CiscoNcs 1002 Version-
   CiscoNcs 1004 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 540 Version-
   CiscoNcs 540l Version-
   CiscoNcs 5500 Version-
   CiscoNcs 560 Version-
   CiscoNcs 6000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.31% 0.792
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
psirt@cisco.com 8.6 3.9 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H