Cisco IOS XR Software DHCP Version 4 Server DoS (cisco-sa-iosxr-dhcp-dos-pjPVReLU)

high Nessus Plugin ID 153207

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco IOS XR is affected by a vulnerability in the DHCP version 4 (DHCPv4) server feature that allows an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because certain DHCPv4 messages are improperly validated when they are processed by an affected device. An attacker could exploit this vulnerability by sending a malformed DHCPv4 message to an affected device. A successful exploit could allow the attacker to cause a NULL pointer dereference, resulting in a crash of the dhcpd process. While the dhcpd process is restarting, which may take up to approximately two minutes, DHCPv4 server services are unavailable on the affected device. This could temporarily prevent network access to clients that join the network during that time period. Note: Only the dhcpd process crashes and eventually restarts automatically. The router does not reload.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvw95930

See Also

http://www.nessus.org/u?ce07f05c

http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-74637

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw95930

Plugin Details

Severity: High

ID: 153207

File Name: cisco-sa-iosxr-dhcp-dos-pjPVReLU-iosxr.nasl

Version: 1.7

Type: combined

Family: CISCO

Published: 9/10/2021

Updated: 4/22/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-34737

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios_xr

Required KB Items: Host/Cisco/IOS-XR/Version, Host/Cisco/IOS-XR/Model

Exploit Ease: No known exploits are available

Patch Publication Date: 9/8/2021

Vulnerability Publication Date: 9/8/2021

Reference Information

CVE: CVE-2021-34737

CWE: 476

CISCO-SA: cisco-sa-iosxr-dhcp-dos-pjPVReLU

IAVA: 2021-A-0407-S

CISCO-BUG-ID: CSCvw95930