CVE-2004-0589
published 2004-08-06CVE-2004-0589: Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.02%
85.9th percentile
Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | 11.1 – 12.2\(14\)sx2 | — |
| cisco | ios_malformed_bgp_packet_causes_reload | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Malformed BGP Packet Causes Reload
vendor_cisco·2004-06-16
CVE-2004-0589 CWE-399 Cisco IOS Malformed BGP Packet Causes Reload
Cisco IOS Malformed BGP Packet Causes Reload
A Cisco device running IOS and enabled for the Border Gateway Protocol
(BGP) is vulnerable to a Denial of Service (DOS) attack from a malformed BGP
packet. The BGP protocol is not enabled by default, and must be configured in
order to accept traffic from an explicitly defined peer. Unless the malicious
traffic appears to be sourced from a configured, trusted peer, it would be
difficult to inject a malformed packet.
Cisco has made free software available to address this problem.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040616-bgp.
Cisco
Cisco IOS Malformed BGP Packet Causes Reload
vendor_cisco
CVE-2004-0589 Cisco IOS Malformed BGP Packet Causes Reload
CVE-2004-0589: Cisco IOS Malformed BGP Packet Causes Reload
A Cisco device running IOS and enabled for the Border Gateway Protocol (BGP) is vulnerable to a Denial of Service (DOS) attack from a malformed BGP packet. The BGP protocol is not enabled by default, and must be configured in order to accept traffic from an explicitly defined peer. Unless the malicious traffic appears to be sourced from a configured, trusted peer, it would be difficult to inject a malformed packet. Cisco has made free software available to address this problem. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040616-bgp .
CWE: CWE-399, CWE-399
Bug IDs: CSCdu53656, CSCea28131, CSCdx23494
GHSA
GHSA-7h4g-phhp-6jm7: Cisco IOS 11
ghsa_unreviewed·2022-04-29
CVE-2004-0589 [MEDIUM] GHSA-7h4g-phhp-6jm7: Cisco IOS 11
Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/cisco-sa-20040616-bgp.shtmlhttp://www.kb.cert.org/vuls/id/784540https://exchange.xforce.ibmcloud.com/vulnerabilities/16427https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4948http://www.cisco.com/warp/public/707/cisco-sa-20040616-bgp.shtmlhttp://www.kb.cert.org/vuls/id/784540https://exchange.xforce.ibmcloud.com/vulnerabilities/16427https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4948
2004-08-06
Published