cbcvebase.
CVE-2007-5381
published 2007-10-12

CVE-2007-5381: Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute…

PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
14.68%
96.3th percentile
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.

Affected

1429 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

port515
commandtelnet 10.0.0.1 515
  • Monitor for inbound TCP connections to port 515 (LPD) originating from source ports other than 515, which is the documented exploit trigger condition.
  • Detect SNMP write (SET) operations targeting the sysName OID (system.sysName.0) with unusually long string values, which is the prerequisite step to stage the buffer overflow.
  • Alert on any TCP connection to port 515 (LPD service) on Cisco IOS devices, especially if preceded by an SNMP SET to sysName — the two-step attack chain requires both actions in sequence.
  • ·The LPD service must be running on the Cisco IOS device for exploitation to be possible. Disabling LPD eliminates the attack surface entirely.
  • ·SNMP community string 'private' with write access is used in the exploit PoC; restricting SNMP write access or using strong community strings mitigates the hostname-change prerequisite.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.