PT-2008-2747 · Cisco · Cisco Ios

Ryan Giobbi

·

Published

2008-03-26

·

Updated

2017-09-29

·

CVE-2008-1153

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.1 through 12.4
Description The issue allows remote attackers to cause a denial of service via a crafted IPv6 packet to the device, potentially causing the device to crash or blocking an interface. This can occur when IPv4 UDP services and the IPv6 protocol are enabled. Successful exploitation will prevent the interface from receiving any additional traffic, except for the Resource Reservation Protocol (RSVP) service, which will cause the device to crash if exploited.
Recommendations For Cisco IOS versions 12.1 through 12.4, update to a fixed software version to address this issue. As a temporary workaround, consider disabling IPv6 protocol or restricting IPv4 UDP services to minimize the risk of exploitation. Additionally, restricting access to the vulnerable interface can help mitigate the effects of the vulnerability.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-1153

Affected Products

Cisco Ios