Advisory on Vulnerabilities in Cisco Multiple Products

- NIC-CERT/2023-03/057
- Date: 2023-03-10
- CVE ID: Multiple
- Severity: High
Advisory on Vulnerabilities in Cisco Multiple Products
-
- Description:
Cisco has released security updates to address vulnerability in Cisco software. A remote attacker could exploit some of the vulnerability to take control of an affected system.
B. Affected Products:
The following table gives the list of products affected, CVE IDs and overview of vulnerabilities:
Name of the Vulnerability |
CVE ID |
Affected Product |
Remediation |
Cisco IOS XR Software for ASR 9000 Series Routers Bidirectional Forwarding Detection Denial of Service Vulnerability |
CVE-2023-20049 |
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco IOS XR 64-bit Software and have BFD hardware offload enabled for any of the installed line cards:
|
There are no workarounds that address these vulnerabilities. |
Cisco IOS XR Software Bootloader Unauthenticated Information Disclosure Vulnerability |
CVE-2023-20064 |
At the time of publication, this vulnerability affected the following Cisco devices if they were running a vulnerable release of Cisco IOS XR Software:
|
There are no workarounds that address this vulnerability. |
Users are advised to visit following URL’s and follow the steps to apply fixes.
https://tools.cisco.com/security/center/publicationListing.x
D. References:
https://tools.cisco.com/security/center/publicationListing.x