Vulnerability Note VU#341288
Cisco IOS fails to properly process certain packets containing a crafted IP option
Overview
Cisco IOS software contains a vulnerablity that may allow an attacker to execute arbitrary code or create a denial of service condition.
Description
Cisco IOS is an operating system that is used on Cisco network devices. The Internet Control Message Protocol (ICMP) is a protocol commonly used for testing connections and diagnosing problems. A vulnerability exists in the way Cisco IOS processes the following types of packets sent to an IPv4 address on an affected system.
An attacker may be able to exploit the vulnerability by sending a packet with a specially crafted IP header to an IP address on a vulnerable system. Note that ICMP is often enabled on network infrastructure switches and routers for troubleshooting purposes. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary code or create a denial of service condition. Note that a vulnerable system would have to be the destination for the specially crafted packet. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Cisco Systems, Inc. | Affected | - | 24 Jan 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml
- http://www.cisco.com/univercd/cc/td/doc/product/lan/c2900xl/29_35wc/sc/swgvlans.htm#xtocid119662
- http://en.wikipedia.org/wiki/Access_control_list
- http://en.wikipedia.org/wiki/IPv6
- http://tools.ietf.org/html/rfc791
- http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml#fixes
- http://en.wikipedia.org/wiki/Cisco_IOS
- http://tools.ietf.org/html/rfc792
- http://www.cisco.com/warp/public/707/cisco-sa-20070124-bundle.shtml
- http://secunia.com/advisories/23867/
- http://www.cisco.com/en/US/products/products_security_response09186a00807cb0da.html
- http://www.securityfocus.com/bid/22211
Credit
Thanks to Cisco for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 24 Jan 2007
- Date First Published: 24 Jan 2007
- Date Last Updated: 31 Jan 2007
- Severity Metric: 18.15
- Document Revision: 19
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.