Vulnerable Products:
This vulnerability affects the following Cisco products if they have the TWAMP server feature enabled:
IOS Software is affected with or without debugs enabled. IOS XE Software
Releases 16.6.1 through 17.2.3 are affected only if the debug command debug ip sla trace twamp connection is active. All other releases (up to the first fixed release) do not require debugs to be enabled to be affected by this vulnerability.
IOS XR Software is affected only if the debug command debug ipsla trace twamp connection is active.
For information about which Cisco software releases are vulnerable, see the Fixed Software ["#fs"] section of this advisory. Determine the TWAMP Server Configuration Cisco IOS and Cisco IOS XE Software
To determine whether the TWAMP server is enabled on a device, use the show running-config | include ip sla server twamp CLI command. If the TWAMP server feature is enabled, the device is affected by this vulnerability.
The following example shows the output for a device that has the TWAMP server enabled:
Router#show running-config | include ip sla server twamp ip sla server twamp Router#
If the command returns no output or an error, the device is not affected.
To determine whether the TWAMP debugs are enabled on a device that is running Cisco IOS XE Software, use the show debug | include TWAMP Server Connection TRACE CLI command.
The following example shows the output for a device that has the IP SLA debugs enabled:
Router#show debug | include TWAMP Server Connection TRACE IPPM TWAMP Server Connection TRACE debug all Router#
If the command returns no output or an error, the device does not have the debugs enabled.
Cisco IOS XR Software
To determine whether the TWAMP server is enabled on a device, use the show running-config ipsla server twamp CLI command. If the TWAMP server feature is enabled, the device is affected by this vulnerability.
The following example shows the output...
12.2(58)EX12.2(58)EZ12.2(6)I112.2(60)EZ12.2(60)EZ112.2(60)EZ1012.2(60)EZ1112.2(60)EZ1212.2(60)EZ1312.2(60)EZ14+605 more16.1.116.1.216.1.316.10.116.10.1a16.10.1b16.10.1c16.10.1d16.10.1e16.10.1f+458 more24.1.124.1.224.2.124.2.1124.2.224.2.2024.3.16.5.16.5.156.5.2+82 moreExploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:NI:NA:H8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H