PT-2007-5611 · Cisco · Cisco Ios
Dario Ciccarone
·
Published
2007-08-20
·
Updated
2011-05-18
·
CVE-2007-4430
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.0 through 12.4
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in a device restart and BGP routing table rebuild, by using certain regular expressions in a "show ip bgp regexp" command. Unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Recommendations
For Cisco IOS versions 12.0 through 12.4, consider restricting access to the "show ip bgp regexp" command to prevent unauthenticated remote attacks, and limit the use of anonymous telnet and Looking Glass access until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios