PT-2007-5611 · Cisco · Cisco Ios
Dario Ciccarone
·
Publicado
2007-08-20
·
Atualizado
2011-05-18
·
CVE-2007-4430
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.0 through 12.4
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in a device restart and BGP routing table rebuild, by using certain regular expressions in a "show ip bgp regexp" command. Unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Recommendations
For Cisco IOS versions 12.0 through 12.4, consider restricting access to the "show ip bgp regexp" command to prevent unauthenticated remote attacks, and limit the use of anonymous telnet and Looking Glass access until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Ios