CVE-2023-20233

A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by sending crafted CCMs to an affected device. A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:7.9.0:*:*:*:*:*:*:*

History

25 Jan 2024, 17:15

Type Values Removed Values Added
CWE CWE-476

18 Sep 2023, 13:48

Type Values Removed Values Added
First Time Cisco
Cisco ios Xr
CWE CWE-354
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:cisco:ios_xr:7.9.0:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
References (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKtĀ - (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKtĀ - Vendor Advisory

13 Sep 2023, 17:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 17:15

Updated : 2024-01-25 17:15


NVD link : CVE-2023-20233

Mitre link : CVE-2023-20233

CVE.ORG link : CVE-2023-20233


JSON object : View

Products Affected

cisco

  • ios_xr
CWE
CWE-354

Improper Validation of Integrity Check Value

CWE-476

NULL Pointer Dereference