Impact
This vulnerability arises from internal, incorrect calculation logic in Cisco IOS XR Software. The flaw, classified under CWE-682, can produce unintended results during packet processing or configuration handling, leading to system instability or failures. The resulting miscalculation could cause denial of service if errors propagate to critical routing decisions. No explicit exploitation path is detailed, but the possibility exists.
Affected Systems
Affected products are Cisco IOS XR Software. The advisory indicates that all versions prior to the hardening release are impacted; no specific build or release numbers are listed, and the hardening release resolves the calculation issues.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no publicly reported exploitation has been documented. Based on the description, the likely attack vector could involve malformed traffic or configuration input that triggers the incorrect calculation, but explicit details are lacking. Considering the severity and potential system disruption, the risk is significant.
OpenCVE Enrichment