PT-2011-1003 · Cisco · Cisco Ios+1

Published

2011-09-28

·

Updated

2022-06-02

·

CVE-2011-0946

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.1 through 12.4 Cisco IOS versions 15.0 through 15.1 Cisco IOS XE version 3.1.xSG
Description The NAT implementation in the software allows remote attackers to cause a denial of service, resulting in a device reload or hang, via malformed NetMeeting Directory LDAP traffic. The issue can be triggered by sending specially crafted network requests, exploiting vulnerabilities in the NAT implementation of protocols such as NetMeeting Directory, Session Initiation Protocol, and H.323 protocol.
Recommendations For Cisco IOS versions 12.1 through 12.4, update to a version that fixes the Bug ID CSCtd10712 issue. For Cisco IOS versions 15.0 through 15.1, update to a version that fixes the Bug ID CSCtd10712 issue. For Cisco IOS XE version 3.1.xSG, update to a version that fixes the Bug ID CSCtd10712 issue. As a temporary workaround, consider restricting access to the vulnerable NAT implementation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00025
CVE-2011-0946

Affected Products

Cisco Ios
Cisco Ios Xe