CVE-2019-16023 describes multiple denial-of-service vulnerabilities in Cisco IOS XR Software's Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality. An unauthenticated, remote attacker can exploit these flaws by sending crafted BGP EVPN update messages with malformed attributes to an affected system. This can cause the BGP process to restart, leading to a denial-of-service condition. The vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for a configured BGP peer to trigger the DoS remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.6.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.6.1:*:*:*:*:*:*:* | ||
6.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.6.2:*:*:*:*:*:*:* | ||
6.6.25CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:6.6.25:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.