PT-2010-2341 · Cisco · Cisco Ios

Published

2010-03-24

·

Updated

2010-07-13

·

CVE-2010-0584

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS version 12.4
Description A vulnerability in Cisco IOS allows remote attackers to cause a denial of service (device reload) via crafted Skinny Client Control Protocol (SCCP) packets when NAT SCCP fragmentation support is enabled. This issue may be exploited by sending SCCP packets to affected devices. The estimated number of potentially affected devices is not specified.
Recommendations For Cisco IOS version 12.4, update to a version that includes the software updates released by Cisco to address this issue. As a temporary workaround, consider disabling the NAT SCCP fragmentation support feature to mitigate this vulnerability. Restrict access to the SCCP protocol to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0584

Affected Products

Cisco Ios