PT-2008-2165 · Cisco · Supervisor Engine 720+5

Published

2008-03-26

·

Updated

2017-08-08

·

CVE-2008-0537

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Catalyst 6500 Series and Cisco 7600 Router devices with Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), or Route Switch Processor 720 (RSP720) modules, running branches of Cisco IOS based on 12.2
Description The issue allows remote attackers to cause a denial of service via unknown vectors when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link. This can result in a blocked queue, device restart, or memory leak. The vulnerability only affects devices configured for Open Shortest Path First (OSPF) Sham-Link and Multi Protocol Label Switching (MPLS) Virtual Private Networking (VPN), and OSPF and MPLS VPNs are not enabled by default.
Recommendations For Cisco Catalyst 6500 Series and Cisco 7600 Router devices with Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), or Route Switch Processor 720 (RSP720) modules, running branches of Cisco IOS based on 12.2, consider disabling OSPF Sham-Link and MPLS VPN configurations as a temporary workaround until a patch is available. Restrict access to affected interfaces to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-0537

Affected Products

Cisco 7600 Router
Cisco Catalyst 6500 Series
Cisco Ios
Route Switch Processor 720
Supervisor Engine 32
Supervisor Engine 720