HomeSecurityVulnerability in Cisco IOS XR allows hackers to gain elevated privileges

Cisco IOS XR Vulnerability Allows Hackers to Gain Elevated Privileges

A critical vulnerability has been discovered in multicast traceroute version 2 (Mtrace2) of Cisco IOS XR software, which poses significant risks to network security.

Cisco vulnerability

This flaw allows hackers to exhaust the UDP packet memory of affected devices, potentially leading to a denial of service (DoS) and privilege escalation. The vulnerability results from improper packet memory management by the Mtrace2 code.

Hackers can exploit it by sending specially crafted packets to the affected device, which can exhaust the incoming UDP packet buffer. This exhaustion prevents the device from processing packets of higher-level protocols based on UDP, thus causing a DoS condition. Notably, this vulnerability can also be exploited via IPv4 and IPv6 protocols.

Read more: Cisco's merchandise store targeted by cyberattack

CVE -2024-20304 This issue affects Cisco IOS XR software and is related to the handling of certain Ethernet frames on various Cisco Network Convergence System (NCS) platforms. This flaw allows an attacker to cause high-priority packets to be dropped, leading to a denial of service (DoS) condition.

CVE -2024-20317 This flaw affects software , specifically targeting the handling of certain Ethernet frames on various Cisco Network Convergence System (NCS) platforms. It allows an attacker to cause high-priority packets to be dropped, leading to a denial of service (DoS) condition.

CVE -2024-20406 is a vulnerability in Cisco IOS XR software that affects the processing of certain Ethernet on various Cisco Network Convergence System (NCS) platforms. This flaw allows an attacker to cause critical packets to be dropped, resulting in a denial of service (DoS) condition.

CVE -2024-20398 is a vulnerability affecting Cisco IOS XR software, specifically in the processing of certain Ethernet frames on various Cisco Network Convergence System (NCS) platforms. This flaw allows an attacker to cause high-priority packets to be dropped, leading to a denial of service (DoS) condition.

Affected services

The vulnerability affects Cisco devices running specific versions of Cisco IOS XR software.

  • Versions 7.7.1 to 7.11.2: Affected if Multicast RPM Packet Manager is installed and active, regardless of multicast configuration.
  • Versions 24.1.1 and later: Affected when the multicast RPM is installed and active, and when the device is configured for multicast.

See more: Cisco fixes critical vulnerability in Cisco ISE

Devices running versions prior to 7.7.1 are not affected. To determine if a device is vulnerable, administrators can use specific commands to check whether multicast RPM is enabled and whether the device is processing Mtrace2 packets. Cisco has released software updates to address this vulnerability, but no workarounds are available.

However, certain preventive measures can contribute to reducing the risk:

Disable Multicast RPM: If multicast configuration is not necessary, it is recommended to disable and remove multicast RPM to close the vulnerable UDP port.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Implement Infrastructure Access Control Lists (iACLs): Deploy iACLs to enforce traffic policies and minimize the risk and impact of direct attacks on the infrastructure.

For administrators, the active installation summary can be used to verify whether RPM multicast is active. In addition, the lpts pifib hardware import command can provide brief information. In addition, the include 33433 command can check whether Mtrace2 processing is enabled.

Cisco IOS XR

Read also: Cisco gains significant strength from Robust Intelligence

Cisco has provided free software updates to address this vulnerability. Customers with service contracts are advised to apply for updates through their established channels. Customers without service contracts are advised to contact the Cisco Technical Assistance Center (TAC) to obtain the necessary updates.

Administrators should immediately apply these updates to protect network from potential exploits.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS