CVE-2007-5134

CWE-2644 documents4 sources
Severity
5.0MEDIUM
EPSS
0.7%
top 28.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 1

Description

Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDcisco/catalyst_6500_ws-svc-nam-12.2\(1a\), 3.1\(1a\)+1
NVDcisco/catalyst_6500_ws-svc-nam-22.2\(1a\), 3.1\(1a\)+1
NVDcisco/catalyst_6500_ws-x6380-nam2.1\(2\), 3.1\(1a\)+1
NVDcisco/catalyst_7600_ws-svc-nam-12.2\(1a\), 3.1\(1a\)+1
NVDcisco/catalyst_7600_ws-svc-nam-22.2\(1a\), 3.1\(1a\)+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2j9f-fxq3-5v7w: Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might a2022-05-01
CVEList
CVE-2007-5134: Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might a2007-09-27

📋Vendor Advisories

1
Cisco
Cisco IOS on Catalyst 6500 and Cisco 7600 Access Control List Bypass Vulnerability2007-09-26
CVE-2007-5134 (MEDIUM CVSS 5) | Cisco Catalyst 6500 and Cisco 7600 | cvebase.io