A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establishing a TCP session and then sending a malicious TCP segment via IPv4 to an affected device. This cannot be exploited via IPv6, as the Raw Socket Transport feature does not support IPv6 as a network layer protocol.
2019-09-25T21:15:10.657
2024-11-21T04:23:16.193
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xe | 16.9 | Yes |
Operating System | cisco | ios_xe | 16.10.1 | Yes |
Hardware | cisco | asr_902 | - | No |
Hardware | cisco | asr_902u | - | No |
Hardware | cisco | asr_903 | - | No |
Hardware | cisco | asr_907 | - | No |
Hardware | cisco | asr_914 | - | No |