cbcvebase.
CVE-2007-4286
published 2007-08-09

CVE-2007-4286: Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service…

PriorityP261critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
19.41%
97.1th percentile
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios_next_hop_resolution_protocol

Detection & IOCsextracted from sources · hover to see the quote

filenamec7100-jk9o3s-mz.123-12e.bin
filenamec7200-jk8o3s-mz.122-40.bin
filenamec3640-js-mz.122-15.T17.bin
otherIP protocol number 54 (NHRP direct over IP)
  • ·NHRP is not enabled by default; only devices with NHRP explicitly configured (e.g., DMVPN tunnels) are vulnerable. Disabling NHRP is the stated workaround.
  • ·All three NHRP transport modes are affected: Layer 2, GRE/mGRE tunnels, and direct IP (proto 54) — detection must cover all three paths.
  • ·Two separate Cisco bug IDs track this issue: CSCin95836 for non-12.2 mainline releases and CSCsi23231 for 12.2 mainline releases — ensure the correct patch is applied per IOS train.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco8.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.