PT-2007-5611 · Cisco · Cisco Ios

Dario Ciccarone

·

Published

2007-08-20

·

Updated

2011-05-18

·

CVE-2007-4430

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.0 through 12.4
Description The issue allows context-dependent attackers to cause a denial of service, resulting in a device restart and BGP routing table rebuild, by using certain regular expressions in a "show ip bgp regexp" command. Unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Recommendations For Cisco IOS versions 12.0 through 12.4, consider restricting access to the "show ip bgp regexp" command to prevent unauthenticated remote attacks, and limit the use of anonymous telnet and Looking Glass access until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4430

Affected Products

Cisco Ios