
====================================================================

                              CERT-Renater

                 Note d'Information No. 2017/VULN134
_____________________________________________________________________

DATE                : 04/05/2017

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco IOS XR.

=====================================================================
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-ios-xr
____________________________________________________________________

Cisco Security Advisory: Cisco IOS XR Software Denial of Service
Vulnerability

Advisory ID: cisco-sa-20170503-ios-xr

Revision: 1.0

For Public Release: 2017 May 3 16:00 GMT

Last Updated: 2017 May 3 16:00 GMT

CVE ID(s): CVE-2017-3876

CVSS Score v(3): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

+---------------------------------------------------------------------

Summary
=======
A vulnerability in the Event Management Service daemon (emsd) of Cisco
IOS XR routers, could allow an unauthenticated, remote attacker to
cause a denial of service (DoS) condition on the affected device.

The vulnerability is due to improper handling of gRPC requests. An
attacker could exploit this vulnerability by repeatedly sending
unauthenticated gRPC requests to the affected device. A successful
exploit could allow the attacker to crash the device in such a manner
that manual intervention is required to recover.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-ios-xr
["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-ios-xr"]

==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================



