CVE-2008-1152
published 2008-03-27CVE-2008-1152: The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.71%
88.5th percentile
The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8pm-776c-452x: Cisco IOS 12
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2011-1625 [MEDIUM] CWE-362 GHSA-v8pm-776c-452x: Cisco IOS 12
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka Bug ID CSCtf74999, a different vulnerability than CVE-2007-0199, CVE-2008-1152, and CVE-2009-0629.
GHSA
GHSA-mx4j-m8xg-9rjj: The data-link switching (DLSw) component in Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2008-1152 [HIGH] GHSA-mx4j-m8xg-9rjj: The data-link switching (DLSw) component in Cisco IOS 12
The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.
Cisco
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
vendor_cisco·2008-03-26·CVSS 7.8
CVE-2007-0199 [HIGH] CWE-399 Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
Cisco IOS contains multiple vulnerabilities in the Data-link Switching
(DLSw) feature that may result in a reload or memory leaks when processing
specially crafted UDP or IP Protocol 91 packets.
Cisco has released software updates that address these vulnerabilities. Workarounds are available to mitigate the effects of these
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080326-dlsw.
Note: The March 26, 2008 publication includes five Security Advisories.
The Advisories all affect Cisco's Internetwork Operating System (IOS). Each
Advisory lists the releases that correct the vulnerability described in the
Advisory, and the Advisories also d
Cisco
Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
vendor_cisco
CVE-2008-1152 Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
CVE-2008-1152: Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
Cisco IOS contains multiple vulnerabilities in the Data-link Switching (DLSw) feature that may result in a reload or memory leaks when processing specially crafted UDP or IP Protocol 91 packets. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCsf28840, CSCsk73104, CSCsk73104, CSCsk73104
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/29507http://www.cisco.com/en/US/products/products_security_advisory09186a0080969866.shtmlhttp://www.securityfocus.com/bid/28465http://www.securitytracker.com/id?1019712http://www.us-cert.gov/cas/techalerts/TA08-087B.htmlhttp://www.vupen.com/english/advisories/2008/1006/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41482https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5821http://secunia.com/advisories/29507http://www.cisco.com/en/US/products/products_security_advisory09186a0080969866.shtmlhttp://www.securityfocus.com/bid/28465http://www.securitytracker.com/id?1019712http://www.us-cert.gov/cas/techalerts/TA08-087B.htmlhttp://www.vupen.com/english/advisories/2008/1006/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41482https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5821
2008-03-27
Published