MEDIUM · 6.5

CVE-2019-16027

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, ...

Vulnerability Description

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS–IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (SNMP) request for specific Object Identifiers (OIDs) by the IS–IS process. An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. A successful exploit could allow the attacker to cause a DoS condition in the IS–IS process.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xr4.3.2
CiscoXr 12404-
CiscoXr 12406-
CiscoXr 12410-
CiscoXr 12416-
CiscoNcs 6000-
CiscoNcs 6008-
CiscoNcs 5001-
CiscoNcs 5002-
CiscoNcs 5011-
CiscoNcs 5500-
CiscoNcs 5501-
CiscoNcs 5502-
CiscoNcs 5508-
CiscoNcs 5516-
CiscoCrs-
CiscoXrv 9000-
CiscoNcs 540-
CiscoNcs 560-
CiscoAsr 9000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-16027?

CVE-2019-16027 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, ...

How severe is CVE-2019-16027?

CVE-2019-16027 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-16027?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr, Cisco Xr 12404, Cisco Xr 12406, Cisco Xr 12410, Cisco Xr 12416.