Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.
2016-01-05T02:59:05.427
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xr | 4.2.0 | Yes |
Operating System | cisco | ios_xr | 4.3.0 | Yes |
Operating System | cisco | ios_xr | 5.0.0 | Yes |
Operating System | cisco | ios_xr | 5.1.0 | Yes |
Operating System | cisco | ios_xr | 5.2.0 | Yes |
Operating System | cisco | ios_xr | 5.2.2 | Yes |
Operating System | cisco | ios_xr | 5.2.4 | Yes |
Operating System | cisco | ios_xr | 5.3.0 | Yes |
Operating System | cisco | ios_xr | 5.3.2 | Yes |