Cisco IOS XR
cpe:2.3:h:cisco:ios_xr:*:*:*:*:*:*:*, +3 more
- <= 7.11
- <= 24.1
- <= 24.3
- <= 24.4
- <= 25.1
- <= 25.2
A denial-of-service vulnerability has been identified in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software. This issue allows an unauthenticated, adjacent attacker to trigger a broadcast storm, causing a DoS condition on the affected device. The vulnerability arises from the way Cisco IOS XR processes high volumes of ARP traffic on the management interface. An attacker could exploit this by sending excessive traffic, overwhelming the device's ARP processing capabilities. The result is degraded performance, loss of management connectivity, and complete unresponsiveness, leading to a DoS condition.
Exploitation of this vulnerability causes the device to drop packets from an internal queue associated with the ARP process, leading to congestion and unresponsiveness. This behavior generates continuous log entries indicating packet drops, further evidencing the denial-of-service condition.
Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. Consult the Cisco IOS XR Software Security Advisory Bundled Publication for specific upgrade instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.