Cisco IOS XR Software DHCP Version 6 Denial of Service Vulnerability

Related Vulnerabilities: CVE-2014-3271  

A vulnerability in the DHCP version 6 (DHCPv6) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the DHCPv6 process on an affected device to crash. The vulnerability is due to incorrect handling of malformed DHCPv6 packets. An attacker could exploit this vulnerability by sending a malformed DHCPv6 packet to an affected device configured with DHCPv6 server functionality. An exploit could allow the attacker to cause the DHCPv6 process on an affected device to crash. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker may need access to trusted, internal networks to send malformed DCHPv6 packets to a targeted device. In addition, the targeted device must be configured with DCHPv6 server functionality. These requirements may reduce the possibility of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.