The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Cisco IOS-XR

security announce CVE-2018-0286

Cisco IOS XR: denial of service via netconf

Synthesis of the vulnerability

An attacker can generate a fatal error via netconf of Cisco IOS XR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-iosxr, CSCvg95792, CVE-2018-0286, VIGILANCE-VUL-26033.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a fatal error via netconf of Cisco IOS XR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer threat announce CVE-2018-0241

Cisco IOS XR: denial of service via UDP Broadcast Forwarding

Synthesis of the vulnerability

An attacker can generate a fatal error via UDP Broadcast Forwarding of Cisco IOS XR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 19/04/2018.
Identifiers: CERTFR-2018-AVI-194, cisco-sa-20180418-iosxr, CSCvi35625, CVE-2018-0241, VIGILANCE-VUL-25924.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a fatal error via UDP Broadcast Forwarding of Cisco IOS XR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

threat alert CVE-2018-0167 CVE-2018-0175

Cisco IOS / IOS XE / IOS XR: memory corruption via LLDP

Synthesis of the vulnerability

An attacker can generate a memory corruption via LLDP of Cisco IOS / IOS XE / IOS XR, in order to trigger a denial of service, and possibly to run code.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 29/03/2018.
Identifiers: CERTFR-2018-AVI-156, cisco-sa-20180328-lldp, CSCuo17183, CSCvd73487, CSCvd73664, CVE-2018-0167, CVE-2018-0175, VIGILANCE-VUL-25697.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a memory corruption via LLDP of Cisco IOS / IOS XE / IOS XR, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability alert CVE-2018-0132

Cisco IOS XR: denial of service via routing table corruption

Synthesis of the vulnerability

An attacker can trigger a corruption of the routing table in Cisco IOS XR, in order to block traffic forwarding.
Severity: 2/4.
Creation date: 08/02/2018.
Identifiers: cisco-sa-20180207-iosxr, CVE-2018-0132, VIGILANCE-VUL-25250.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can trigger a corruption of the routing table in Cisco IOS XR, in order to block traffic forwarding.
Full Vigil@nce bulletin... (Free trial)

security alert CVE-2018-0136

Cisco ASR: denial of service via IPv6 segmentation

Synthesis of the vulnerability

An attacker can send segmented IPv6 packets to Cisco ASR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 01/02/2018.
Identifiers: CERTFR-2018-AVI-064, cisco-sa-20180131-ipv6, CVE-2018-0136, VIGILANCE-VUL-25189.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can send segmented IPv6 packets to Cisco ASR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

threat bulletin CVE-2017-12355

Cisco IOS XR: denial of service via LPTS

Synthesis of the vulnerability

An attacker can send malicious LPTS packets to Cisco IOS XR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 30/11/2017.
Identifiers: cisco-sa-20171129-ios-xr, CSCvf76332, CVE-2017-12355, VIGILANCE-VUL-24579.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can send malicious LPTS packets to Cisco IOS XR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer weakness bulletin CVE-2017-12270

Cisco IOS XR: denial of service via gRPC

Synthesis of the vulnerability

An attacker can generate a fatal error via gRPC of Cisco IOS XR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 05/10/2017.
Identifiers: CERTFR-2017-AVI-333, cisco-sa-20171004-ncs, CSCvb99388, CVE-2017-12270, VIGILANCE-VUL-24029.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a fatal error via gRPC of Cisco IOS XR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

cybersecurity announce CVE-2017-6731

Cisco IOS XR: denial of service via MSDP

Synthesis of the vulnerability

An attacker can send malicious MSDP packets to Cisco IOS XR, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 06/07/2017.
Identifiers: CERTFR-2017-AVI-202, cisco-sa-20170705-iosxr, CSCvd94828, CVE-2017-6731, VIGILANCE-VUL-23142.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Cisco IOS XR product has a service to manage received MSDP packets.

However, when malicious MSDP packets are received, a fatal error occurs.

An attacker can therefore send malicious MSDP packets to Cisco IOS XR, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer threat alert CVE-2017-6728

Cisco IOS XR: privilege escalation via CLI

Synthesis of the vulnerability

An attacker can bypass restrictions via CLI of Cisco IOS XR, in order to escalate his privileges.
Severity: 2/4.
Creation date: 06/07/2017.
Identifiers: CERTFR-2017-AVI-202, cisco-sa-20170705-ios, CSCvb99389, CVE-2017-6728, VIGILANCE-VUL-23141.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions via CLI of Cisco IOS XR, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2017-6719

Cisco IOS XR: privilege escalation via CLI

Synthesis of the vulnerability

An attacker can bypass restrictions via CLI of Cisco IOS XR, in order to escalate his privileges.
Severity: 2/4.
Creation date: 22/06/2017.
Revision date: 27/06/2017.
Identifiers: CERTFR-2017-AVI-191, cisco-sa-20170621-ios, CSCvb99406, CVE-2017-6719, VIGILANCE-VUL-23059.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions via CLI of Cisco IOS XR, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Cisco IOS-XR: