CVE-2019-1910
published 2019-08-07CVE-2019-1910: A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could…
PriorityP434high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.45%
36.5th percentile
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are configured with the IS–IS routing protocol. Cisco has confirmed that this vulnerability affects both Cisco IOS XR 32-bit Software and Cisco IOS XR 64-bit Software.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | carrier_routing_system | — | — |
| cisco | cisco_ios_xr_software | >= unspecified < 6.6.3 | 6.6.3 |
| cisco | ios_xr | < 6.6.3 | 6.6.3 |
| cisco | ios_xr | — | — |
| msrc | azure_stack | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_msrc7.5HIGH
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Stack Spoofing Vulnerability
vendor_msrc·2019-11-12·CVSS 7.5
CVE-2019-1234 [HIGH] Azure Stack Spoofing Vulnerability
Azure Stack Spoofing Vulnerability
Description: A spoofing vulnerability exists when Azure Stack fails to validate certain requests. An attacker who successfully exploited the vulnerability could make requests to internal Azure Stack resources.
An attacker could exploit the vulnerability by sending a specially crafted request to the Azure Stack user portal.
The update addresses the vulnerability by changing how Azure Stack handles certain requests.
Azure Stack: Azure Stack
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://docs.microsoft.com/en-us/azure-stack/operator/release-notes-security-updates?view=azs-1910
Cisco
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
vendor_cisco·2019-08-07·CVSS 7.4
CVE-2019-1910 [HIGH] CWE-20 Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition.
The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition.
Cisco has released software updates that addres
Cisco
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1910 Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
CVE-2019-1910: Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
A vulnerability in the implementation of the Intermediate System-to-Intermediate System (IS-IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS-IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS-IS area to unexpectedly restart the IS-IS process, resulting in a DoS condition. Cisco has released software updat
GHSA
GHSA-25g3-p7c7-27pp: A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Softwar
ghsa_unreviewed·2022-05-24
CVE-2019-1910 [HIGH] CWE-20 GHSA-25g3-p7c7-27pp: A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Softwar
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are con
No detection rules found.
No writeups or analysis indexed.
2019-08-07
Published