PT-2006-5549 · Cisco · Cisco Ios
Fx
·
Published
2006-09-13
·
Updated
2018-10-17
·
CVE-2006-4774
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS version 12.1(19)
Description
The VLAN Trunking Protocol (VTP) feature in Cisco IOS contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability exists because the VTP feature does not properly handle malformed packets sent from the local network. An attacker residing on the local network segment could exploit this vulnerability via a crafted summary packet to cause a DoS condition. To exploit this vulnerability, an attacker must reside on the local network segment and send a crafted summary packet to a device supporting VTP. The device must be configured as either client or server for VTP, and the packets must be received on a trunk enabled port. Exploitation causes a DoS condition only until the device reboots, but repeated attacks could cause an extended DoS condition.
Recommendations
For Cisco IOS version 12.1(19), update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to trunk enabled ports and configuring VTP domain passwords to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios