Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers ARP Denial of Service Vulnerability
TL;DR 📌
A high-severity vulnerability has been identified in Cisco IOS XE Software for ASR 903 Aggregation Services Routers, allowing unauthenticated adjacent attackers to trigger a denial of service (DoS) condition. Cisco has released software updates to address this issue, but there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated adjacent attacker to exploit the system. This vulnerability arises from improper memory management when processing Address Resolution Protocol (ARP) messages. By sending crafted ARP messages at a high rate, an attacker could exhaust system resources, leading to a reload of the active route switch processor (RSP). If there is no redundant RSP, the router will reload.
Affected products 🖥️
This vulnerability affects Cisco ASR 903 Aggregation Services Routers with RSP3C running vulnerable releases of Cisco IOS XE Software, regardless of device configuration. Products confirmed not vulnerable include IOS Software, IOS XE Software on devices other than ASR 903, IOS XR Software, Meraki products, and NX-OS Software.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds that directly address this vulnerability. However, customers can monitor the RSS memory usage of the uea_mgr process to avoid unexpected reloads. If memory usage approaches critical levels, a planned reload of the RSP can be scheduled. Customers should evaluate the applicability of this mitigation in their own environments.
Risk in context 🎯
With a CVSS score of 7.4, this vulnerability is classified as high severity. The risk is significant as it allows for denial of service attacks that can disrupt network operations. Organizations using affected devices should prioritize applying the necessary software updates to mitigate this risk.
Fast facts ⚡
- Vulnerability: ARP Denial of Service
- CVSS Score: 7.4 (High)
- Affected Product: Cisco ASR 903 Aggregation Services Routers with RSP3C
- Exploit Type: Unauthenticated, adjacent attacker
- Impact: Denial of service leading to router reload
For leadership 🧭
Executive summary. ASR 903 routers fitted with the RSP3C processor can be knocked offline by an attacker on the local network segment sending high rates of malformed ARP traffic, with no authentication required. There is no workaround, so patching should be scheduled as a priority change once fixed IOS XE releases are confirmed for your train.
Why it matters:
- The flaw sits in Cisco Express Forwarding’s handling of ARP messages on ASR 903 routers with RSP3C, so any device on the same broadcast domain can trigger it without credentials.
- A sustained flood of crafted ARP messages exhausts memory and forces a reload of the active route switch processor; without a redundant RSP fitted, the entire router reloads and drops all traffic it was carrying.
- Cisco confirms the vulnerability applies regardless of configuration, so standard hardening or ACLs on the box will not by themselves prevent exposure.
- No workaround exists — the only mitigation short of upgrading is watching RSS memory usage of the uea_mgr process and scheduling a planned reload before it crashes unexpectedly.
Now / Next / Later:
- Now: Identify every ASR 903 router in the estate fitted with RSP3C and check whether it has a redundant RSP installed, since single-RSP units face a full outage rather than a failover.
- Next: Upgrade affected devices to the first fixed IOS XE release for their train in the next available change window, prioritising routers without RSP redundancy or with exposed adjacent-access segments.
- Later: Until upgrades are complete, monitor uea_mgr RSS memory usage on ASR 903/RSP3C devices and schedule controlled reloads ahead of thresholds to avoid unplanned outages caused by ARP-driven memory exhaustion.