7.4

CVE-2019-1749

Cisco Aggregation Services Router 900 Route Switch Processor 3 OSPFv2 Denial of Service Vulnerability

A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficiently validates ingress traffic on the ASIC used on the RSP3 platform. An attacker could exploit this vulnerability by sending a malformed OSPF version 2 (OSPFv2) message to an affected device. A successful exploit could allow the attacker to cause a reload of the iosd process, triggering a reload of the affected device and resulting in a DoS condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version 3.13.6as
Cisco ≫ Ios Xe Version 3.16.0as
Cisco ≫ Ios Xe Version 3.16.1as
Cisco ≫ Ios Xe Version 3.16.2as
Cisco ≫ Ios Xe Version 3.16.3as
Cisco ≫ Ios Xe Version 3.16.4bs
Cisco ≫ Ios Xe Version 3.16.4cs
Cisco ≫ Ios Xe Version 3.16.4ds
Cisco ≫ Ios Xe Version 3.16.4es
Cisco ≫ Ios Xe Version 3.16.4gs
Cisco ≫ Ios Xe Version 3.16.4s
Cisco ≫ Ios Xe Version 3.16.5as
Cisco ≫ Ios Xe Version 3.16.5s
Cisco ≫ Ios Xe Version 3.16.6bs
Cisco ≫ Ios Xe Version 3.16.6s
Cisco ≫ Ios Xe Version 3.16.7bs
Cisco ≫ Ios Xe Version 3.16.7s
Cisco ≫ Ios Xe Version 3.16.8s
Cisco ≫ Ios Xe Version 3.17.0s
Cisco ≫ Ios Xe Version 3.17.1s
Cisco ≫ Ios Xe Version 3.17.3s
Cisco ≫ Ios Xe Version 3.17.4s
Cisco ≫ Ios Xe Version 3.18.0s
Cisco ≫ Ios Xe Version 3.18.0sp
Cisco ≫ Ios Xe Version 3.18.1bsp
Cisco ≫ Ios Xe Version 3.18.1gsp
Cisco ≫ Ios Xe Version 3.18.1hsp
Cisco ≫ Ios Xe Version 3.18.1isp
Cisco ≫ Ios Xe Version 3.18.1s
Cisco ≫ Ios Xe Version 3.18.1sp
Cisco ≫ Ios Xe Version 3.18.2s
Cisco ≫ Ios Xe Version 3.18.2sp
Cisco ≫ Ios Xe Version 3.18.3s
Cisco ≫ Ios Xe Version 3.18.3sp
Cisco ≫ Ios Xe Version 3.18.4s
Cisco ≫ Ios Xe Version 3.18.4sp
Cisco ≫ Ios Xe Version 16.5.1
Cisco ≫ Ios Xe Version 16.5.2
Cisco ≫ Ios Xe Version 16.5.3
Cisco ≫ Ios Xe Version 16.6.1
Cisco ≫ Ios Xe Version 16.6.2
Cisco ≫ Ios Xe Version 16.6.3
Cisco ≫ Ios Xe Version 16.6.4
Cisco ≫ Ios Xe Version 16.7.1
Cisco ≫ Ios Xe Version 16.7.2
Cisco ≫ Ios Xe Version 16.8.1
Cisco ≫ Ios Xe Version 16.8.1b
Cisco ≫ Ios Xe Version 16.8.1c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.442
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
NIST 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:N/I:N/A:C
Cisco PSIRT 7.4 2.8 4
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/107615
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-rsp3-ospf
Patch
Vendor Advisory