CVE-2008-2060
published 2008-06-18CVE-2008-2060: Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support…
PriorityP431high7.8CVSS 2.0
AVNACMAuNCPINAC
EPSS
1.71%
74.7th percentile
Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a "specific series of jumbo Ethernet frames."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system_jumbo_frame | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:M/Au:N/C:P/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Intrusion Prevention System Jumbo Frame Denial of Service
vendor_cisco·2008-06-18·CVSS 7.8
CVE-2008-2060 [HIGH] CWE-399 Cisco Intrusion Prevention System Jumbo Frame Denial of Service
Cisco Intrusion Prevention System Jumbo Frame Denial of Service
Cisco Intrusion Prevention System (IPS) platforms that have gigabit
network interfaces installed and are deployed in inline mode contain a denial
of service vulnerability in the handling of jumbo Ethernet frames. This
vulnerability may lead to a kernel panic that requires a power cycle to recover
platform operation. Platforms deployed in promiscuous mode only or that do not
contain gigabit network interfaces are not vulnerable.
Cisco has released software updates that address this vulnerability. There is a workaround for this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080618-ips.
Cisco
Cisco Intrusion Prevention System Jumbo Frame Denial of Service
vendor_cisco
CVE-2008-2060 Cisco Intrusion Prevention System Jumbo Frame Denial of Service
CVE-2008-2060: Cisco Intrusion Prevention System Jumbo Frame Denial of Service
Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable. Cisco has released software updates that address this vulnerability. There is a workaround for this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080618-ips .
CWE: CWE-399, CWE-399
Bug IDs: CSCso64762
GHSA
GHSA-vjff-mhv7-25px: Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5
ghsa_unreviewed·2022-05-01
CVE-2008-2060 [HIGH] GHSA-vjff-mhv7-25px: Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5
Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a "specific series of jumbo Ethernet frames."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/30767http://www.cisco.com/en/US/products/products_security_advisory09186a00809b3842.shtmlhttp://www.securityfocus.com/bid/29791http://www.securitytracker.com/id?1020326http://www.vupen.com/english/advisories/2008/1872/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43166http://secunia.com/advisories/30767http://www.cisco.com/en/US/products/products_security_advisory09186a00809b3842.shtmlhttp://www.securityfocus.com/bid/29791http://www.securitytracker.com/id?1020326http://www.vupen.com/english/advisories/2008/1872/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43166
2008-06-18
Published