Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106251
Category:CISCO
Title:Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability (cisco-sa-20160914-iosxr)
Summary:A vulnerability in the OSPFv3 processing of Cisco IOS XR; Software for Cisco Network Convergence System (NCS) 6000 Series devices could allow an; unauthenticated, remote attacker to cause a reload of the OSPFv3 process and result in a limited; denial of service (DoS) condition on an affected device.
Description:Summary:
A vulnerability in the OSPFv3 processing of Cisco IOS XR
Software for Cisco Network Convergence System (NCS) 6000 Series devices could allow an
unauthenticated, remote attacker to cause a reload of the OSPFv3 process and result in a limited
denial of service (DoS) condition on an affected device.

Vulnerability Insight:
The vulnerability is due to insufficient logic in the
processing of crafted OSPFv3 packets. An attacker could exploit this vulnerability by sending
crafted OSPFv3 packets to be processed by an affected device.

Vulnerability Impact:
An exploit could allow the attacker to cause a reload of the
OSPFv3 process and cause a limited DoS condition on the affected device.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-1433
BugTraq ID: 92961
http://www.securityfocus.com/bid/92961
Cisco Security Advisory: 20160914 Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-iosxr
http://www.securitytracker.com/id/1036832
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.