Cisco IOS XR Software Network Convergence System DoS (cisco-sa-l2services-2mvHdNuC)

high Nessus Plugin ID 214885

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco IOS XR is affected by a vulnerability.

- A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect classification of certain types of Ethernet frames that are received on an interface. An attacker could exploit this vulnerability by sending specific types of Ethernet frames to or through the affected device. A successful exploit could allow the attacker to cause control plane protocol relationships to fail, resulting in a DoS condition. For more information, see the section of this advisory. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. (CVE-2024-20317)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwh30122

See Also

http://www.nessus.org/u?debabde2

http://www.nessus.org/u?a636b5a5

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh30122

Plugin Details

Severity: High

ID: 214885

File Name: cisco-sa-l2services-2mvHdNuC-iosxr.nasl

Version: 1.2

Type: combined

Family: CISCO

Published: 2/3/2025

Updated: 2/6/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2024-20317

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios_xr

Required KB Items: Host/Cisco/IOS-XR/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 9/11/2024

Vulnerability Publication Date: 9/11/2024

Reference Information

CVE: CVE-2024-20317

CWE: 684

CISCO-SA: cisco-sa-l2services-2mvHdNuC

IAVA: 2024-A-0573-S

CISCO-BUG-ID: CSCwh30122