PT-2005-3360 · Cisco · Cisco Ios Xr+1
Published
2005-07-29
·
Updated
2017-10-11
·
CVE-2005-2451
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.0 through 12.4
Cisco IOS XR versions prior to 3.2
Description
The issue allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet. Only devices that have been explicitly configured to process IPv6 traffic are affected. Upon successful exploitation, the device may reload or be open to further exploitation.
Recommendations
For Cisco IOS versions 12.0 through 12.4, update to a version that addresses this vulnerability.
For Cisco IOS XR versions prior to 3.2, update to version 3.2 or later.
As a temporary workaround, consider disabling IPv6 traffic processing on affected devices until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xr