CVE-2008-1153
published 2008-03-27CVE-2008-1153: Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash…
PriorityP431high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
5.58%
92.1th percentile
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-676g-35q7-rhh4: Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2008-1153 [HIGH] GHSA-676g-35q7-rhh4: Cisco IOS 12
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.
Cisco
Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
vendor_cisco·2008-03-26·CVSS 7.8
CVE-2008-1153 [HIGH] CWE-399 Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
A device running Cisco IOS software that has Internet Protocol version
6 (IPv6) enabled may be subject to a denial of service (DoS) attack. For the
device to be affected by this vulnerability the device also has to have certain
Internet Protocol version 4 (IPv4) User Datagram Protocol (UDP) services
enabled. To exploit this vulnerability an offending IPv6 packet must be
targeted to the device. Packets that are routed throughout the router can not
trigger this vulnerability. Successful exploitation will prevent the interface
from receiving any additional traffic. The only exception is Resource
Reservation Protocol (RSVP) service, which if exploited, will cause the device
to crash. Only the interface on which
Cisco
Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
vendor_cisco
CVE-2008-1153 Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
CVE-2008-1153: Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers
A device running Cisco IOS software that has Internet Protocol version 6 (IPv6) enabled may be subject to a denial of service (DoS) attack. For the device to be affected by this vulnerability the device also has to have certain Internet Protocol version 4 (IPv4) User Datagram Protocol (UDP) services enabled. To exploit this vulnerability an offending IPv6 packet must be targeted to the device. Packets that are routed throughout the router can not trigger this vulnerability. Successful exploitation will prevent the interface from receiving any additional traffic. The only exception is Resource Reservation Protocol (RSVP) service, which if exploited, will cause the device to crash. Only the interf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/29507http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtmlhttp://www.kb.cert.org/vuls/id/936177http://www.securityfocus.com/bid/28461http://www.securitytracker.com/id?1019713http://www.us-cert.gov/cas/techalerts/TA08-087B.htmlhttp://www.vupen.com/english/advisories/2008/1006/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41475https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5860http://secunia.com/advisories/29507http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtmlhttp://www.kb.cert.org/vuls/id/936177http://www.securityfocus.com/bid/28461http://www.securitytracker.com/id?1019713http://www.us-cert.gov/cas/techalerts/TA08-087B.htmlhttp://www.vupen.com/english/advisories/2008/1006/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41475https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5860
2008-03-27
Published