PT-2008-5157 · Cisco · Cisco Ios

Published

2008-09-26

·

Updated

2022-06-02

·

CVE-2008-3803

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.0 through 12.4
Description A logic error in the software, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target to be used. This issue allows remote attackers to read traffic from other VPNs in certain circumstances.
Recommendations For Cisco IOS versions 12.0 through 12.4, consider disabling the MPLS VPN configuration with extended communities until a fix is available to prevent potential traffic exposure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-3803

Affected Products

Cisco Ios