PT-2008-5160 · Cisco · Ubr10012+3
Published
2008-09-26
·
Updated
2022-06-02
·
CVE-2008-3806
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices
Description
The issue allows remote attackers to cause a denial of service, resulting in a device or linecard reload, by sending crafted UDP packets to 127.0.0.0/8 addresses intended for IPC communication within the device.
Recommendations
For Cisco IOS versions 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices, consider restricting access to external UDP packets sent to 127.0.0.0/8 addresses as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco 10000
Cisco Ios
Ubr10012
Ubr7200