Cisco IOS XR Software Route Processor Denial of Service Vulnerability (cisco-sa-20120530-iosxr)

high Nessus Plugin ID 71435

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

Cisco IOS XR Software contains a vulnerability when handling crafted packets that may result in a denial of service condition. The vulnerability only exists on Cisco 9000 Series Aggregation Services Routers (ASR) Route Switch Processor (RSP-4G and RSP-8G), Route Switch Processor 440 (RSP440), and Cisco Carrier Routing System (CRS) Performance Route Processor (PRP). The vulnerability is a result of improper handling of crafted packets and could cause the route processor, which processes the packets, to be unable to transmit packets to the fabric.

Solution

Apply the relevant patch referenced in Cisco Security Advisory cisco-sa-20120530-iosxr.

See Also

http://www.nessus.org/u?c29bbd37

Plugin Details

Severity: High

ID: 71435

File Name: cisco-sa-20120530-iosxr.nasl

Version: 1.7

Type: combined

Family: CISCO

Published: 12/14/2013

Updated: 4/8/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2012-2488

Vulnerability Information

CPE: cpe:/o:cisco:ios_xr

Required KB Items: Host/Cisco/IOS-XR/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/23/2013

Vulnerability Publication Date: 10/23/2013

Reference Information

CVE: CVE-2012-2488

BID: 53728