CVE-2023-20233
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by sending crafted CCMs to an affected device. A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.
Una vulnerabilidad en la función Connectivity Fault Management (CFM) del software Cisco IOS XR podría permitir que un atacante remoto no autenticado cause una condición de denegación de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe al procesamiento incorrecto de mensajes de verificación de continuidad (CCM) no válidos. Un atacante podría aprovechar esta vulnerabilidad enviando CCM manipulados a un dispositivo afectado. Una explotación existosa podría permitir al atacante provocar que el servicio CFM se bloquee cuando un usuario muestra información sobre los puntos finales de mantenimiento (MEP) para los MEP pares en un dispositivo afectado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-27 CVE Reserved
- 2023-09-13 CVE Published
- 2024-08-02 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-354: Improper Validation of Integrity Check Value
- CWE-476: NULL Pointer Dereference
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | < 7.5.4 Search vendor "Cisco" for product "Ios Xr" and version " < 7.5.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | >= 7.6 < 7.6.3 Search vendor "Cisco" for product "Ios Xr" and version " >= 7.6 < 7.6.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | >= 7.7 < 7.7.21 Search vendor "Cisco" for product "Ios Xr" and version " >= 7.7 < 7.7.21" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | >= 7.8 < 7.8.2 Search vendor "Cisco" for product "Ios Xr" and version " >= 7.8 < 7.8.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 7.9.0 Search vendor "Cisco" for product "Ios Xr" and version "7.9.0" | - |
Affected
|