Guest

Preview Tool

Cisco Bug: CSCur62957 - Cisco IOS XR Software BVI Routed Packet Denial of Service Vulnerability

Last Modified

Aug 20, 2018

Products (8)

  • Cisco ASR 9000 Series Aggregation Services Routers
  • Cisco ASR 9922 Router
  • Cisco IOS XR Software
  • Cisco ASR 9010 Router
  • Cisco ASR 9904 Router
  • Cisco ASR 9006 Router
  • Cisco ASR 9001 Router
  • Cisco ASR 9912 Router

Known Affected Releases

4.3.1.BASE 4.3.2.BASE 4.3.4.BASE 5.1.2.BASE 5.1.3.BASE 5.2.2.BASE 5.3.2.BASE

Description (partial)

Symptom:
A vulnerability in the packet-processing code of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers (ASR) could allow an unauthenticated, remote attacker to cause a lockup and eventual reload of a network processor chip and the line card that is processing traffic. Only Typhoon-based line cards on Cisco ASR 9000 Series Aggregation Services Routers are affected by this vulnerability.

The vulnerability is due to improper processing of packets that are routed via the bridge-group virtual interface (BVI) when any of the following features are configured: Unicast Reverse Path Forwarding (uRPF), policy-based routing (PBR), quality of service (QoS), or access control lists (ACLs). An attacker could exploit this vulnerability by sending IPv4 packets through an affected device that is configured to route them via the BVI interface. A successful exploit could allow the attacker to cause a lockup and eventual reload of a network processor chip and the line card that is processing traffic, leading to a denial of service (DoS) condition.

Cisco has released free software updates that address this vulnerability. There are no workarounds to address this vulnerability.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150415-iosxr

Conditions:
Please see the published Cisco Security Advisory.

Related Community Discussions

5.1.3 Feature Pack (FP) Content discussion board
This community page to share the content, delivery dates and more details on Feature Packs.   FP2 Content All DDTSs tracking changes in FP2. Features: ---------   Features CSCur18267: ASR9k - 512 Bundle Ethernet enhancement   Features CSCun46269: Need changes in LSPV and PI FIB to send engine type for hashing.   Features CSCur74985: BFD on bundle vlan not working on cluster after upgrade to 5.1.3   Features CSCun11455: Need changes in cpp ucode to send eng type for punt pkt.   Features CSCug63470: ...
Latest activity: Mar 15, 2016
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.