Security Advisory

CVE-2017-12270

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-10-05 07:00:00
Last updated 2024-08-05 18:36:54
Assigner cisco
State PUBLISHED

Description

A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the emsd service stops. The vulnerability is due to the softwares inability to process HTTP/2 packets. An attacker could exploit this vulnerability by sending a malformed HTTP/2 frame to the affected device. A successful exploit could allow the attacker to create a DoS condition when the emsd service stops. Cisco Bug IDs: CSCvb99388.