CVE-2008-3803
published 2008-09-26CVE-2008-3803: A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a…
medium5.1CVSS 3.1
AVNACHAuNCPIPAP
A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_mpls_vpn_may_leak | — | — |
Cisco
Cisco IOS MPLS VPN May Leak Information
vendor_cisco·2008-09-24·CVSS 5.1
CVE-2008-3803 [MEDIUM] Cisco IOS MPLS VPN May Leak Information
Cisco IOS MPLS VPN May Leak Information
Devices running Cisco IOS versions 12.0S, 12.2, 12.3 or 12.4 and
configured for Multiprotocol Label Switching (MPLS) Virtual Private Networks
(VPNs) or VPN Routing and Forwarding Lite (VRF Lite) and using Border Gateway
Protocol (BGP) between Customer Edge (CE) and Provider Edge (PE) devices may
permit information to propagate between VPNs.
Workarounds are available to help mitigate this
vulnerability.
This issue is triggered by a logic error when processing
extended communities on the PE device.
This issue cannot be deterministically exploited by an
attacker.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are
available.
This advisory is posted at
https://sec.cloudapps.cisco.c
Cisco
Cisco IOS MPLS VPN May Leak Information
vendor_cisco
CVE-2008-3803 Cisco IOS MPLS VPN May Leak Information
CVE-2008-3803: Cisco IOS MPLS VPN May Leak Information
Devices running Cisco IOS versions 12.0S, 12.2, 12.3 or 12.4 and configured for Multiprotocol Label Switching (MPLS) Virtual Private Networks (VPNs) or VPN Routing and Forwarding Lite (VRF Lite) and using Border Gateway Protocol (BGP) between Customer Edge (CE) and Provider Edge (PE) devices may permit information to propagate between VPNs.
Bug IDs: CSCec12299, CSCee83237, CSCee83237, CSCee83237, CSCec12299
GHSA
GHSA-2wcv-w38q-52h8: A "logic error" in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2008-3803 [MEDIUM] CWE-20 GHSA-2wcv-w38q-52h8: A "logic error" in Cisco IOS 12
A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014a9.shtmlhttp://www.securityfocus.com/bid/31366http://www.securitytracker.com/id?1020940http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5919http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014a9.shtmlhttp://www.securityfocus.com/bid/31366http://www.securitytracker.com/id?1020940http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5919
2008-09-26
Published