VDB
CVE-2023-20233
CVE-2023-20233
PUBLISHED
Es besteht eine Schwachstelle in Cisco IOS XR. Dieser Fehler besteht in der Funktion "Connectivity Fault Management" (CFM) der XR-Software aufgrund einer fehlerhaften Verarbeitung von ungültigen Continuity-Check-Meldungen. Ein entfernter Angreifer kann diese Schwachstelle ausnutzen, um einen Denial-of-Service-Zustand zu verursachen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.12% · 30.2th percentile
Risk Scores
EPSS Score
0.12%
30.2th percentile
Exploit Intelligence
- cisco-sa-ios-xr-cfm-3pWN8MKt (circl)
Timeline
- Sep 13, 2023 CVE Published
- Sep 14, 2023 EPSS Score
- Oct 16, 2023 EPSS Score
- Nov 18, 2023 EPSS Score
- Dec 20, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
- Feb 23, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- May 30, 2024 EPSS Score
- Jul 1, 2024 EPSS Score
- Aug 2, 2024 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2355.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2355 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-L9zOkBz5 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKt advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnx-acl-PyzDkeYF advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-comp3acl-vGmp6BQ3 advisory