Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Network
0

CVE-2019-16027

Disclosure Date: January 23, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS–IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS–IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS–IS process.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.5 Medium
Impact Score:
3.6
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • cisco

Products

  • ios xr 4.3.2,
  • ios xr 5.2.5,
  • ios xr 6.1.2,
  • ios xr 6.1.3,
  • ios xr 6.1.4,
  • ios xr 6.2.2,
  • ios xr 6.2.25,
  • ios xr 6.2.3,
  • ios xr 6.3.15,
  • ios xr 6.3.2,
  • ios xr 6.3.3,
  • ios xr 6.4.2,
  • ios xr 6.5.2,
  • ios xr 6.5.3,
  • ios xr 6.6.1,
  • ios xr 6.6.2,
  • ios xr 6.6.25

Additional Info

Technical Analysis