Cisco IOS XR是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XR 6.6.1之后版本中边界网关协议(BGP)以太网VPN(EVPN)功能的实现存在资源管理错误漏洞,该漏洞源于程序没有正确处理包含有特制EVPN属性的BGP更新消息。攻击者可通过发送属性格式错误的BGP EVPN更新消息利用该漏洞造成BGP进程意外重新启动,从而导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco IOS XR Software | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-3569 | 8.6 HIGH | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities |
| CVE-2019-16023 | Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities | |
| CVE-2019-16021 | Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities | |
| CVE-2019-16025 | Cisco Emergency Responder Stored Cross-Site Scripting Vulnerability | |
| CVE-2019-16028 | Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Byp | |
| CVE-2019-1736 | Multiple Cisco UCS-Based Products UEFI Secure Boot Bypass Vulnerability | |
| CVE-2019-1888 | Cisco Unified Contact Center Express Privilege Escalation Vulnerability | |
| CVE-2019-1947 | Cisco Email Security Appliance Denial of Service Vulnerability | |
| CVE-2019-1983 | Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of S | |
| CVE-2020-3116 | Cisco Webex Centers Denial of Service Vulnerability | |
| CVE-2020-3117 | Cisco Web Security Appliance and Cisco Content Security Management Appliance HTTP Header I | |
| CVE-2020-3124 | Cisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery Vulnerability | |
| CVE-2020-3130 | Cisco Unity Connection Directory Traversal Vulnerability | |
| CVE-2020-3133 | Cisco Email Security Appliance Content Filter Bypass Vulnerability | |
| CVE-2020-3135 | Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability | |
| CVE-2020-3137 | Cisco Email Security Appliance Cross-Site Scripting Vulnerability | |
| CVE-2020-3143 | Cisco TelePresence Collaboration Endpoint, TelePresence Codec, and RoomOS Software Path Tr | |
| CVE-2019-15283 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-16017 | Cisco Unified Customer Voice Portal Insecure Direct Object Reference Vulnerability | |
| CVE-2019-16009 | Cisco IOS and Cisco IOS XE Software Web UI Cross-Site Request Forgery Vulnerability |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet