CVE-2019-16027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
26/01/2020
Last modified:
12/05/2022

Description

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS–IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS–IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS–IS process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios_xr:4.3.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:xr_12404:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:xr_12406:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:xr_12410:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:xr_12416:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:5.2.5:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.2.2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.2.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.2.25:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.3.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.4.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ncs_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ncs_6008:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.1.3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:6.1.4:*:*:*:*:*:*:*