CVE-2007-0199
published 2007-01-11CVE-2007-0199: The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid…
medium5CVSS 3.1
AVNACLAuNCNINAP
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 12.4 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-v8pm-776c-452x: Cisco IOS 12
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2011-1625 [MEDIUM] CWE-362 GHSA-v8pm-776c-452x: Cisco IOS 12
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka Bug ID CSCtf74999, a different vulnerability than CVE-2007-0199, CVE-2008-1152, and CVE-2009-0629.
GHSA
GHSA-9673-77f3-57fv: The Data-link Switching (DLSw) feature in Cisco IOS 11
ghsa_unreviewed·2022-05-01
CVE-2007-0199 [MEDIUM] GHSA-9673-77f3-57fv: The Data-link Switching (DLSw) feature in Cisco IOS 11
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."
Cisco
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
vendor_cisco·2008-03-26·CVSS 7.8
CVE-2007-0199 [HIGH] CWE-399 Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
Cisco IOS contains multiple vulnerabilities in the Data-link Switching
(DLSw) feature that may result in a reload or memory leaks when processing
specially crafted UDP or IP Protocol 91 packets.
Cisco has released software updates that address these vulnerabilities. Workarounds are available to mitigate the effects of these
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080326-dlsw.
Note: The March 26, 2008 publication includes five Security Advisories.
The Advisories all affect Cisco's Internetwork Operating System (IOS). Each
Advisory lists the releases that correct the vulnerability described in the
Advisory, and the Advisories also d
Cisco
DLSw Vulnerability
vendor_cisco·2007-01-10·CVSS 3.3
CVE-2007-0199 [LOW] CWE-399 DLSw Vulnerability
DLSw Vulnerability
A vulnerability exists in the Data-link Switching (DLSw) feature in
Cisco IOS where an invalid value in a DLSw message could result in a reload of
the DLSw device. Successful exploitation of this vulnerability requires that an
attacker be able to establish a DLSw connection to the device.
There are workarounds available for this vulnerability, as detailed in
the Workarounds section below.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070110-dlsw
Cisco
DLSw Vulnerability
vendor_cisco
CVE-2007-0199 DLSw Vulnerability
CVE-2007-0199: DLSw Vulnerability
A vulnerability exists in the Data-link Switching (DLSw) feature in Cisco IOS where an invalid value in a DLSw message could result in a reload of the DLSw device. Successful exploitation of this vulnerability requires that an attacker be able to establish a DLSw connection to the device. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCsf28840, CSCsf28840, CSCsf28840
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/32683http://secunia.com/advisories/23697http://securitytracker.com/id?1017498http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtmlhttp://www.securityfocus.com/bid/21990http://www.vupen.com/english/advisories/2007/0139https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5714http://osvdb.org/32683http://secunia.com/advisories/23697http://securitytracker.com/id?1017498http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtmlhttp://www.securityfocus.com/bid/21990http://www.vupen.com/english/advisories/2007/0139https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5714
2007-01-11
Published