HomeSecurityCisco NCS 6000 and CRS-X routing devices vulnerable to DoS attacks

Cisco NCS 6000 and CRS-X routing devices vulnerable to DoS attacks

A vulnerability has been identified in two versions of Cisco IOS XR software running on the NCS 6000 and CRS-X routing devices, which could lead to a denial-of-service (DoS).

Cisco Routing Devices
The vulnerability is remotely exploitable by an unauthorized user and is due to improper parsing of malformed IPv6 carrying extension headers.

IOS XR software versions prior to 5.3.2 available for the NCS 6000 are vulnerable, while in the case of CRS-X (400-Gbps Modular Services Card and 400-Gbps Forwarding Processor Cards) the vulnerable software versions are prior to 5.3.0. The prerequisite for a successful attack is the activation of IPv6.

Cisco says in a security advisory that the vulnerability is only triggered if IPv6 traffic is being processed by the devices. If that traffic is intended for them, then the vulnerability, identified as CVE-2015-0618, cannot be exploited.

Cisco admits that some intermediate devices could mitigate the risk, but a malformed packet could be sent from a remote network and terminate the hardware's activity, a condition that could be prolonged by repeated exploitation of the vulnerability.

There are no solutions to mitigate or eliminate the risk of the attack, but the company has integrated a security update into the aforementioned versions of IOS XR for the affected products.

The vulnerability has a Common Vulnerability Scoring System score of 7.1, but no exploit has been made at this time, according to data collected by the Cisco Product Security Incident Response Team (PSIRT).

The vulnerability CVE-2015-0618 was not reported by third parties, but was discovered through internal testing conducted by the company.

As general safeguards, administrators are advised to apply the latest updates delivered through the usual customer update channels and to grant network access only to trusted users. Setting up a strong firewall should improve the security of these products.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS