CVE-2010-0576
published 2010-03-25CVE-2010-0576: Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.97%
85.8th percentile
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a crafted LDP packet, aka Bug IDs CSCsz45567 and CSCsj25893.
Affected
187 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
vendor_cisco·2010-03-24·CVSS 7.8
CVE-2010-0576 [HIGH] CWE-399 Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
A device running Cisco IOS® Software, Cisco
IOS XE Software, or Cisco IOS XR Software is vulnerable to a remote denial of
service (DoS) condition if it is configured for Multiprotocol Label Switching
(MPLS) and has support for Label Distribution Protocol (LDP).
A crafted LDP UDP packet can cause an affected device running Cisco IOS
Software or Cisco IOS XE Software to reload. On devices running affected
versions of Cisco IOS XR Software, such packets can cause the device to restart
the mpls_ldp process.
A system is vulnerable if configured with either LDP or Tag
Distribution Protocol (TDP).
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are available.
Th
Cisco
Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
vendor_cisco
CVE-2010-0576 Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
CVE-2010-0576: Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
A device running Cisco IOS ® Software, Cisco IOS XE Software, or Cisco IOS XR Software is vulnerable to a remote denial of service (DoS) condition if it is configured for Multiprotocol Label Switching (MPLS) and has support for Label Distribution Protocol (LDP). A crafted LDP UDP packet can cause an affected device running Cisco IOS Software or Cisco IOS XE Software to reload. On devices running affected versions of Cisco IOS XR Software, such packets can cause the device to restart the mpls_ldp process. A system is vulnerable if configured with either LDP or Tag Distribution Protocol (TDP). Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCsz45567, CSCs
GHSA
GHSA-jchr-vxfj-2cxw: Unspecified vulnerability in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2010-0576 [HIGH] GHSA-jchr-vxfj-2cxw: Unspecified vulnerability in Cisco IOS 12
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a crafted LDP packet, aka Bug IDs CSCsz45567 and CSCsj25893.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/63188http://secunia.com/advisories/39065http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee2.shtmlhttp://www.securityfocus.com/bid/38938http://www.securitytracker.com/id?1023740http://www.vupen.com/english/advisories/2010/0707https://exchange.xforce.ibmcloud.com/vulnerabilities/57143http://osvdb.org/63188http://secunia.com/advisories/39065http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee2.shtmlhttp://www.securityfocus.com/bid/38938http://www.securitytracker.com/id?1023740http://www.vupen.com/english/advisories/2010/0707https://exchange.xforce.ibmcloud.com/vulnerabilities/57143
2010-03-25
Published