PT-2012-1780 · Cisco · Cisco Ios+1

Publicado

2012-05-02

·

Atualizado

2012-10-30

·

CVE-2011-4007

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 15.0 through 15.1 Cisco IOS XE versions 3.x
Description The issue arises from improper handling of the set mpls experimental imposition command, allowing remote attackers to cause a denial of service, resulting in a device crash. This can be triggered by network traffic that leads to either fragmentation or reassembly.
Recommendations For Cisco IOS versions 15.0 through 15.1, consider disabling the set mpls experimental imposition command as a temporary workaround until a patch is available. For Cisco IOS XE versions 3.x, restrict access to the affected command to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4007

Produtos afetados

Cisco Ios
Cisco Ios Xe