The MPLS-OPS Archive

Cell Relay Retreat>MPLS-OPS Archive>month:2005-Jan> msg00065



[Date Prev][Date Next][Thread Prev][Thread Next]  
  [Date Index][Thread Index][Author Index][Subject Index]

Cisco Vulnerability in MPLS

  • From: Irwin Lazar <ilazar@burtongroup.com>
  • Date: Thu, 27 Jan 2005 16:15:38 -0500
  • Resent-Date: Thu, 27 Jan 2005 16:16:04 -0500
  • User-Agent: Microsoft-Entourage/11.1.0.040913
  • X-Scanned-By: MIMEDefang 2.45
  • X-Security: MIME headers sanitized on host.secure4-hosting.netSee http://www.impsec.org/email-tools/sanitizer-intro.htmlfor details. $Revision: 1.138 $Date: 2003-01-26 11:25:54-08
  • X-SpamProbe: GOOD 0.0000000 d4edd288a90c0a5e7ef1e768d0bdef21

Title: Cisco Vulnerability in MPLS
FYI: This affects routers that are MPLS-capable even if MPLS isn’t enabled..

More info at: http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml
-----

   
Cisco IOS MPLS Packet Processing Denial of Service

Secunia Advisory:    SA14031    Print Advisory  
Release Date:    2005-01-27

Critical:    
Less critical
Impact:    DoS
Where:    From local network
Solution Status:    Vendor Patch

OS:    Cisco IOS 12.x
Cisco IOS R12.x

    Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
A vulnerability has been reported in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error within the processing of MPLS (Multi Protocol Label Switching) packets. This can be exploited to cause a vulnerable device to reload by sending a specially crafted MPLS packet to an interface with MPLS disabled.

Successful exploitation requires support for MPLS; however, it does not have to be configured.

The vulnerability affects the following products with release trains based on 12.1T, 12.2, 12.2T, 12.3, and 12.3T:
* 2600 and 2800 series routers
* 3600, 3700 and 3800 series routers
* 4500 and 4700 series routers
* 5300, 5350 and 5400 series Access Servers

Solution:
See patch matrix in the vendor advisory for information about fixes.
http://www.cisco.com/warp/public...o-sa-20050126-les.shtml#software

Provided and/or discovered by:
Reported by vendor.

Original Advisory:
http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml

Other References:
US-CERT VU#583638:
http://www.kb.cert.org/vuls/id/583638


Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.