Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A high-severity vulnerability has been identified in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software. This flaw could allow unauthenticated remote attackers to cause affected devices to reload, resulting in a denial of service (DoS) condition. Cisco has released fixed software, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the NBAR feature of Cisco IOS XE Software allows unauthenticated, remote attackers to exploit improperly handled malformed Control and Provisioning of Wireless Access Points (CAPWAP) packets. By sending these malformed packets, an attacker can cause the affected device to unexpectedly reload, leading to a denial of service (DoS).

Affected products 🖥️

The following Cisco products are affected if they are running a vulnerable release of Cisco IOS XE Software with the NBAR for CAPWAP feature enabled:

  • 1100 Integrated Services Routers
  • 4000 Series Integrated Services Routers
  • ASR 920 Series Aggregation Services Routers
  • ASR 1000 Series Aggregation Services Routers
  • Catalyst 1101 Rugged Routers
  • Catalyst 8000V Edge Software
  • Catalyst 8200 Series Edge Platforms
  • Catalyst 8300 Series Edge Platforms
  • Catalyst 8500 Edge Platforms
  • Catalyst 8500L Edge Platforms
  • Catalyst IR8300 Rugged Series Routers

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.
Cisco IOS and IOS XE Software Not specified

Workarounds 🧯

There are no workarounds that fully address this vulnerability. However, as a temporary mitigation, customers can disable CAPWAP inspection for NBAR using the command no ip nbar classification tunneled-traffic capwap. It is important to evaluate the impact of this mitigation in your specific environment before implementation.

Risk in context 🎯

The vulnerability has a CVSS score of 8.6, categorizing it as High severity. The risk is heightened as it allows unauthenticated access and can lead to a complete loss of availability for affected devices. Given that there are no effective workarounds, immediate action is recommended to mitigate potential exploitation.

Fast facts ⚡

  • Vulnerability: Cisco IOS XE Software NBAR Denial of Service
  • CVSS Score: 8.6 (High)
  • Impact: Device reload, Denial of Service
  • Exploitation: Requires sending malformed CAPWAP packets
  • Workarounds: None effective; temporary mitigation available

For leadership 🧭

Executive summary. Cisco routers and edge platforms running IOS XE with NBAR’s CAPWAP inspection enabled can be forced to reload by an unauthenticated attacker sending crafted packets, cutting network availability. Given the lack of a full fix workaround and the range of affected routing and edge platforms, this should be scheduled for patching or mitigation within days, not weeks.

Why it matters:

  • The flaw sits in NBAR’s handling of CAPWAP traffic on widely deployed platforms including ASR 1000, ASR 920, Catalyst 8000V/8200/8300/8500 and ISR 1100/4000 series routers.
  • No authentication is needed; a remote attacker only needs to send malformed CAPWAP packets to the device to trigger a reload.
  • There is no workaround that fully resolves the issue – the only temporary option, disabling CAPWAP inspection with ’no ip nbar classification tunneled-traffic capwap’, removes a monitoring capability and needs testing before rollout.
  • A successful reload causes a denial of service on core routing or edge infrastructure, disrupting whatever traffic depends on that device.

Now / Next / Later:

  • Now: Identify which of your Cisco IOS XE devices have NBAR enabled with CAPWAP classification active, and check exposure of those devices to untrusted networks.
  • Next: During your next change window, disable CAPWAP inspection for NBAR with ’no ip nbar classification tunneled-traffic capwap’ on affected devices where it can be tolerated, after assessing the operational impact.
  • Later: Plan and roll out the fixed IOS XE release across all affected router and edge platform models, then remove the interim mitigation once patched.