CVE-2007-5381
published 2007-10-12CVE-2007-5381: Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute…
PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
14.68%
96.3th percentile
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
Affected
1429 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for inbound TCP connections to port 515 (LPD) originating from source ports other than 515, which is the documented exploit trigger condition. ↗
- →Detect SNMP write (SET) operations targeting the sysName OID (system.sysName.0) with unusually long string values, which is the prerequisite step to stage the buffer overflow. ↗
- →Alert on any TCP connection to port 515 (LPD service) on Cisco IOS devices, especially if preceded by an SNMP SET to sysName — the two-step attack chain requires both actions in sequence. ↗
- ·The LPD service must be running on the Cisco IOS device for exploitation to be possible. Disabling LPD eliminates the attack surface entirely. ↗
- ·SNMP community string 'private' with write access is used in the exploit PoC; restricting SNMP write access or using strong community strings mitigates the hostname-change prerequisite. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/37935http://secunia.com/advisories/27169http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.htmlhttp://www.irmplc.com/index.php/155-Advisory-024http://www.kb.cert.org/vuls/id/230505http://www.securityfocus.com/bid/26001http://www.securitytracker.com/id?1018798http://www.vupen.com/english/advisories/2007/3457https://exchange.xforce.ibmcloud.com/vulnerabilities/37046http://osvdb.org/37935http://secunia.com/advisories/27169http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.htmlhttp://www.irmplc.com/index.php/155-Advisory-024http://www.kb.cert.org/vuls/id/230505http://www.securityfocus.com/bid/26001http://www.securitytracker.com/id?1018798http://www.vupen.com/english/advisories/2007/3457https://exchange.xforce.ibmcloud.com/vulnerabilities/37046
2007-10-12
Published