PT-2012-1780 · Cisco · Cisco Ios+1

Published

2012-05-02

·

Updated

2012-10-30

·

CVE-2011-4007

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 15.0 through 15.1 Cisco IOS XE versions 3.x
Description The issue arises from improper handling of the set mpls experimental imposition command, allowing remote attackers to cause a denial of service, resulting in a device crash. This can be triggered by network traffic that leads to either fragmentation or reassembly.
Recommendations For Cisco IOS versions 15.0 through 15.1, consider disabling the set mpls experimental imposition command as a temporary workaround until a patch is available. For Cisco IOS XE versions 3.x, restrict access to the affected command to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4007

Affected Products

Cisco Ios
Cisco Ios Xe