Cisco IOS XE
cpe:2.3:a:cisco:ios_xe:*:*:*:*:*:*:*, +1 more
- < 17.15.4
A denial-of-service vulnerability has been identified in Cisco IOS XE Software for Catalyst 9000 Series Switches. This issue allows an unauthenticated, adjacent attacker to block an egress port, causing it to drop all outbound traffic. The vulnerability arises from improper handling of crafted Ethernet frames. Exploitation involves sending these frames through an affected switch, which can result in the egress port becoming unresponsive and failing to forward traffic, thereby creating a denial-of-service condition.
Exploitation of this vulnerability causes the affected switch's egress port to drop all outbound traffic, leading to a denial-of-service condition on that port.
Cisco has released software updates to address this vulnerability. For instructions on upgrading to a fixed software release, consult the Cisco Security Vulnerability Policy or contact the Cisco Technical Assistance Center (TAC).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.