CVE-2011-0945Missing Release of Memory after Effective Lifetime in Cisco IOS

CWE-3994 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 37.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3
Latest updateMay 17

Description

Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 packet, aka Bug ID CSCth69364.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

NVDcisco/ios191 versions+190
NVDcisco/ios_xe4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-gf95-gf7g-x44x: Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 122022-05-17
CVEList
CVE-2011-0945: Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 122011-10-03

📋Vendor Advisories

1
Cisco
Cisco IOS Software Data-Link Switching Vulnerability2011-09-28
CVE-2011-0945 — Cisco IOS vulnerability | cvebase