Executive brief
A vulnerability in the Cisco ASR 5000 series routers could allow a remote attacker to disrupt VPN services. By sending specially crafted network traffic, an attacker can cause a critical management process to crash and restart. This results in a temporary denial of service for users relying on the device for secure communications.
Technical details
A denial of service vulnerability exists in the ipsecmgr process of Cisco ASR 5000 Software due to a logical error during the parsing of Internet Key Exchange (IKE) packets. An unauthenticated, remote attacker can exploit this by sending malformed IKE packets to the affected system. Successful exploitation causes the ipsecmgr process to crash and reload, disrupting IPsec VPN functionality. The vulnerability was identified through internal testing, and Cisco has released software updates to address the issue. No workarounds are available.
Affected products
- Cisco ASR 5000 Software 20.0.0, 20.0.M0.62842, 20.0.v0, 20.0.M0.63229, 20.1.0, 20.1.a0, 20.1.v0, 21.0.0, 21.0.v0
Timeline
- 2017-01-18: advisory: Initial public release by Cisco
- 2017-01-26: disclosed: NVD publication date