Cisco Family March 2024 First Round Security Update Advisory
Overview
Cisco(https://www.cisco.com) has released a security update that fixes vulnerabilities in products it has been made. users of affected systems are advised to update to the latest version.
Affected Products
Cisco IOS XR Software
Resolved Vulnerabilities
Vulnerability in Cisco IOS XR Software due to insufficient data validation, allowing elevation of privilege to administrator level (CVE-2024-20320, CVSS 7.8) [1]
Vulnerability in Cisco IOS XR Software due to insufficient Ethernet frame handling that could result in a reset of the receive interface network processor (CVE-2024-20318, CVSS 7.4) [2]
Vulnerability in Cisco IOS XR Software due to insufficient data validation, causing the ppp_ma process to crash (CVE-2024-20327, CVSS 7.4) [3]
Vulnerability affecting device functionality due to lack of proper validation of SCP and SFTP CLI input parameters in Cisco IOS XR Software (CVE-2024-20262, CVSS 6.5) [4]
Vulnerability in Cisco IOS XR Software where certain DHCPv4 messages are improperly handled on affected devices, resulting in a crash of the dhcpd process (CVE-2024-20266, CVSS 5.3) [5]
Vulnerability Patches
Product-specific Vulnerability Patches were made available in the 03/13/2024 update. please refer to the ‘Affected Products’ and ‘Fixed Software’ in the product-specific information in the Referenced Sites below to apply the patches.
Referenced Sites
[1] Cisco IOS XR Software SSH Privilege Escalation Vulnerability
[2] Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
[3] Cisco IOS XR Software for ASR 9000 Series Aggregation Services Routers PPPoE Denial of Service Vulnerability
[4] Cisco IOS XR Software Authenticated CLI Secure Copy Protocol and SFTP Denial of Service Vulnerability
[5] Cisco IOS XR Software DHCP Version 4 Server Denial of Service Vulnerability