
====================================================================


                             CERT-Renater

                 Note d'Information No. 2018/VULN151
_____________________________________________________________________

DATE                : 17/04/2018

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco IOS XR.

=====================================================================
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-iosxr
_____________________________________________________________________

Cisco Security Advisory: Cisco IOS XR Software UDP Broadcast Forwarding
Denial of Service Vulnerability

Advisory ID: cisco-sa-20180418-iosxr

Revision: 1.0

For Public Release: 2018 April 18 16:00 GMT

Last Updated: 2018 April 18 16:00 GMT

CVE ID(s): CVE-2018-0241

CVSS Score v(3): 7.4 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

+---------------------------------------------------------------------

Summary

=======

A vulnerability in the UDP broadcast forwarding function of  Cisco IOS
XR Software could allow an unauthenticated, adjacent attacker to cause a
denial of service (DoS) condition on the affected device.

The vulnerability is due to improper handling of UDP broadcast packets
that are forwarded to an IPv4 helper address. An attacker could exploit
this vulnerability by sending multiple UDP broadcast packets to the
affected device. An exploit could allow the attacker to cause a buffer
leak on the affected device, eventually resulting in a DoS condition
requiring manual intervention to recover.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-iosxr

["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-iosxr"]

==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================



