Cisco Family March 2024 First Round Security Update Advisory

Overview

 

Cisco(https://www.cisco.com) has released a security update that fixes vulnerabilities in products it has been made. users of affected systems are advised to update to the latest version.

 

Affected Products

 

Cisco IOS XR Software

 

Resolved Vulnerabilities

 

Vulnerability in Cisco IOS XR Software due to insufficient data validation, allowing elevation of privilege to administrator level (CVE-2024-20320, CVSS 7.8) [1]

Vulnerability in Cisco IOS XR Software due to insufficient Ethernet frame handling that could result in a reset of the receive interface network processor (CVE-2024-20318, CVSS 7.4) [2]

Vulnerability in Cisco IOS XR Software due to insufficient data validation, causing the ppp_ma process to crash (CVE-2024-20327, CVSS 7.4) [3]

Vulnerability affecting device functionality due to lack of proper validation of SCP and SFTP CLI input parameters in Cisco IOS XR Software (CVE-2024-20262, CVSS 6.5) [4]

Vulnerability in Cisco IOS XR Software where certain DHCPv4 messages are improperly handled on affected devices, resulting in a crash of the dhcpd process (CVE-2024-20266, CVSS 5.3) [5]

 

Vulnerability Patches

 

Product-specific Vulnerability Patches were made available in the 03/13/2024 update. please refer to the ‘Affected Products’ and ‘Fixed Software’ in the product-specific information in the Referenced Sites below to apply the patches.

 

Referenced Sites

 

[1] Cisco IOS XR Software SSH Privilege Escalation Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ssh-privesc-eWDMKew3

[2] Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrl2vpn-jesrU3fc

[3] Cisco IOS XR Software for ASR 9000 Series Aggregation Services Routers PPPoE Denial of Service Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-pppma-JKWFgneW

[4] Cisco IOS XR Software Authenticated CLI Secure Copy Protocol and SFTP Denial of Service Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-scp-dos-kb6sUUHw

[5] Cisco IOS XR Software DHCP Version 4 Server Denial of Service Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dhcp-dos-3tgPKRdm