CVE-2008-3805
published 2008-09-26CVE-2008-3805: Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended…
high8.5CVSS 3.1
AVNACLAuNCNIPAC
Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3806.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 10000_ubr10012_ubr7200_series_devices_ipc | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-fqgf-h56q-h3fr: Cisco IOS 12
ghsa_unreviewed·2022-05-02·CVSS 8.5
CVE-2008-3806 [HIGH] GHSA-fqgf-h56q-h3fr: Cisco IOS 12
Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3805.
GHSA
GHSA-chmv-527h-xmg2: Cisco IOS 12
ghsa_unreviewed·2022-05-02·CVSS 8.5
CVE-2008-3805 [HIGH] GHSA-chmv-527h-xmg2: Cisco IOS 12
Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3806.
Cisco
Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
vendor_cisco·2008-09-24·CVSS 8.5
CVE-2008-3805 [HIGH] CWE-399 Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
Cisco 10000, uBR10012 and uBR7200 series devices use a User Datagram
Protocol (UDP) based Inter-Process Communication (IPC) channel that is
externally reachable. An attacker could exploit this vulnerability to cause a
denial of service (DoS) condition on affected devices. No other platforms are
affected.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are
available.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080924-ipc.
Note: The September 24, 2008 IOS Advisory bundled publication includes
twelve Security Advisories. Eleven of the advisories address vulnerabilities in
Cisco's IOS so
Cisco
Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
vendor_cisco
CVE-2008-3805 Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
CVE-2008-3805: Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability
Cisco 10000, uBR10012 and uBR7200 series devices use a User Datagram Protocol (UDP) based Inter-Process Communication (IPC) channel that is externally reachable. An attacker could exploit this vulnerability to cause a denial of service (DoS) condition on affected devices. No other platforms are affected. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCsg15342, CSCsh29217, CSCsg15342, CSCsh29217
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31990http://tools.cisco.com/security/center/viewAlert.x?alertId=16646http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014ae.shtmlhttp://www.securitytracker.com/id?1020935http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5910http://secunia.com/advisories/31990http://tools.cisco.com/security/center/viewAlert.x?alertId=16646http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014ae.shtmlhttp://www.securitytracker.com/id?1020935http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5910
2008-09-26
Published