CVE-2006-4774
published 2006-09-14CVE-2006-4774: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summary frame…
high7.8CVSS 3.1
AVNACLAuNCNINAC
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summary frame with a VTP version field value of 2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-x2rx-8768-8678: Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2005-4826 [HIGH] GHSA-x2rx-8768-8678: Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CVE-2006-4774, CVE-2006-4775, and CVE-2006-4776.
GHSA
GHSA-qw2r-x5rp-6wm2: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2006-4774 [HIGH] GHSA-qw2r-x5rp-6wm2: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summary frame with a VTP version field value of 2.
Cisco
Cisco IOS VTP Malformed Version Denial of Service Vulnerability
vendor_cisco·2006-09-13·CVSS 7.8
CVE-2006-4774 [HIGH] CWE-399 Cisco IOS VTP Malformed Version Denial of Service Vulnerability
Cisco IOS VTP Malformed Version Denial of Service Vulnerability
Cisco IOS contains a vulnerability in the VLAN Trunking Protocol (VTP) that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability exists because the VTP feature in several versions of Cisco IOS software does not properly handle malformed packets sent from the local network. An attacker residing on the local network segment could exploit this vulnerability via a crafted summary packet to cause a DoS condition.
Cisco has confirmed this vulnerability in a security advisory and released updated software to correct it.
To exploit this vulnerability, an attacker must reside on the local network segment and send a crafted summary packet to a device supporting VTP. The devic
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21896http://securitytracker.com/id?1016843http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtmlhttp://www.kb.cert.org/vuls/id/821420http://www.osvdb.org/28775http://www.phenoelit.de/stuff/CiscoVTP.txthttp://www.securityfocus.com/archive/1/445896/100/0/threadedhttp://www.securityfocus.com/archive/1/445938/100/0/threadedhttp://www.securityfocus.com/bid/19998http://www.vupen.com/english/advisories/2006/3600https://exchange.xforce.ibmcloud.com/vulnerabilities/28924http://secunia.com/advisories/21896http://securitytracker.com/id?1016843http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtmlhttp://www.kb.cert.org/vuls/id/821420http://www.osvdb.org/28775http://www.phenoelit.de/stuff/CiscoVTP.txthttp://www.securityfocus.com/archive/1/445896/100/0/threadedhttp://www.securityfocus.com/archive/1/445938/100/0/threadedhttp://www.securityfocus.com/bid/19998http://www.vupen.com/english/advisories/2006/3600https://exchange.xforce.ibmcloud.com/vulnerabilities/28924
2006-09-14
Published