Cisco Carrier Routing System vulnerabilities

8 known vulnerabilities affecting cisco/carrier_routing_system.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2019-1918HIGHCVSS 7.4v6.5.1v6.5.32019-08-07
CVE-2019-1918 [HIGH] CWE-20 CVE-2019-1918: A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS& A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of IS–IS link-state protocol data units (PD
nvd
CVE-2019-1910HIGHCVSS 7.4v7.0.12019-08-07
CVE-2019-1910 [HIGH] CWE-20 CVE-2019-1910: A vulnerability in the implementation of the Intermediate System–to–Intermediate System A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol dat
nvd
CVE-2018-0132HIGHCVSS 8.6v5.3.0.rout2018-02-08
CVE-2018-0132 [HIGH] CWE-119 CVE-2018-0132: A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow a A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB) and the FIB, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect processing of extremely long routing updates. An atta
nvd
CVE-2016-6401MEDIUMCVSS 5.3v5.1.4v5.1_base2016-09-17
CVE-2016-6401 [MEDIUM] CWE-399 CVE-2016-6401: Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 an Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.
nvd
CVE-2015-0618HIGHCVSS 7.1v5.1.3v5.1.42015-02-21
CVE-2015-0618 [HIGH] CWE-19 CVE-2015-0618: Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers, aka Bug ID CSCuq95241.
nvd
CVE-2013-1112MEDIUMCVSS 5.0v3.2.3v3.2.4+36 more2013-01-31
CVE-2013-1112 [MEDIUM] CWE-20 CVE-2013-1112: Cisco Carrier Routing System (CRS) allows remote attackers to cause a denial of service (packet loss Cisco Carrier Routing System (CRS) allows remote attackers to cause a denial of service (packet loss) via short malformed packets that trigger inefficient processing, aka Bug ID CSCud79136.
nvd
CVE-2012-1342MEDIUMCVSS 5.8v3.9.0v4.0.0+1 more2012-08-06
CVE-2012-1342 [MEDIUM] CWE-863 CVE-2012-1342: Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries v Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.
nvd
CVE-2011-3283MEDIUMCVSS 5.0v3.9.12012-05-02
CVE-2011-3283 [MEDIUM] CWE-20 CVE-2011-3283: Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsy Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887.
nvd