SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#201984

Cisco IOS fails to properly handle Next Hop Resolution Protocol packets

Overview

Cisco IOS fails to properly handle Next Hop Resolution Protocol packets, which could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service.

I. Description

Cisco IOS is an operating system that is used on Cisco network devices. Cisco IOS supports a feature called Next Hop Resolution Protocol (NHRP). NHRP is a component of the Dynamic Multipoint Virtual Private Network (DMVPN) feature. NHRP is not enabled by default in Cisco IOS. Cisco IOS fails to properly handle NHRP packets. According to the Cisco Security Advisory,

    NHRP can operate in three ways: at the link layer (Layer 2), over Generic Routing Encapsulation (GRE) and multipoint GRE (mGRE) tunnels and directly on IP (IP protocol number 54). This vulnerability affects all three methods of operation.

Note that exploit code for this vulnerability is publicly available.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service on an affected device.

III. Solution

Apply an update

This issue is addressed in Cisco Security Advisory cisco-sa-20070808-nhrp.

Workarounds

Cisco Security Advisory cisco-sa-20070808-nhrp offers several workarounds, including infrastructure ACLs and Control Plane Policing.

Systems Affected

VendorStatusDate Updated
Cisco Systems, Inc.Vulnerable9-Aug-2007

References


http://www.cisco.com/warp/public/707/cisco-sa-20070808-nhrp.shtml
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080435815.html
http://secunia.com/advisories/26360/

Credit

Thanks to Cisco for reporting this vulnerability, who in turn credit Martin Kluge.

This document was written by Will Dormann.

Other Information

Date Public08/08/2007
Date First Published08/09/2007 02:10:26 PM
Date Last Updated08/10/2007
CERT Advisory 
CVE-ID(s) 
NVD-ID(s) 
US-CERT Technical Alerts 
Metric17.85
Document Revision4

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader