CVE-2017-3876

HIGH

Cisco IOS XR 6.1.1 - Unauthenticated Denial of Service via gRPC Request Handling

Title source: llm
STIX 2.1

Description

A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of gRPC requests. An attacker could exploit this vulnerability by repeatedly sending unauthenticated gRPC requests to the affected device. A successful exploit could allow the attacker to crash the device in such a manner that manual intervention is required to recover. This vulnerability affects all Cisco IOS XR platforms that are running release 6.1.1 of Cisco IOS XR Software when the gRPC service is enabled on the device. The gRPC service is not enabled by default. Cisco Bug IDs: CSCvb14441.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98284
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038393

Scores

CVSS v3 7.5
EPSS 0.0248
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (3)
cisco/ios_xr 6.1.0
cisco/ios_xr 6.1.1
n/a/Cisco IOS XR Cisco IOS XR
Published May 16, 2017
Tracked Since Feb 18, 2026