Cisco IOS XR Software OSPFv3 Denial of Service Vulnerability

Related Vulnerabilities: CVE-2013-5565  

A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a crash of the OSPFv3 process on an affected device. The vulnerability is due to improper parsing of malformed type 1 link-state advertisement (LSA) packets. An attacker could exploit this vulnerability by sending a malformed type 1 LSA packet to a vulnerable device. An exploit could allow the attacker to cause a crash of the OSPFv3 process on an affected device, which may lead to a denial of service (DoS) condition. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker may need access to trusted, internal networks, in which such a device would typically be located, to send malformed type 1 LSA packets to. This access requirement decreases the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.