CVE-2011-3274
published 2011-10-03CVE-2011-3274: Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows…
PriorityP422medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.74%
50.2th percentile
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqhv-wg8r-6hp4: Unspecified vulnerability in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2011-3274 [MEDIUM] GHSA-qqhv-wg8r-6hp4: Unspecified vulnerability in Cisco IOS 12
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.
Cisco
Cisco IOS Software Crafted IPv6 over MPLS Denial of Service Vulnerability
vendor_cisco·2011-09-28·CVSS 6.1
CVE-2011-3274 [MEDIUM] CWE-399 Cisco IOS Software Crafted IPv6 over MPLS Denial of Service Vulnerability
Cisco IOS Software Crafted IPv6 over MPLS Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on a targeted device.
The vulnerability is due to the processing of IP version 6 (IPv6) packets by the vulnerable version of software on an affected device. If an unauthenticated, remote attacker is able to access and send these packets to the vulnerable device, the device may reload, causing a DoS condition and disrupting normal operations.
Cisco has confirmed this vulnerability in a security advisory and has released updated software.
It is likely that an attacker would need to have access to an internal, private network--more specifically to an adjacent network--to send crafted pac
Cisco
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
vendor_cisco·2011-09-28·CVSS 7.8
CVE-2011-3274 [HIGH] Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software is affected by two vulnerabilities that cause a
Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a
Multiprotocol Label Switching (MPLS) domain. These vulnerabilities are:
Crafted IPv6 Packet May Cause MPLS-Configured Device to Reload
ICMPv6 Packet May Cause MPLS-Configured Device to Reload
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate these vulnerabilities are available.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-ipv6mpls.
Note: The September 28, 2011, Cisco IOS Software
Security Advisory bundled publication includes ten C
Cisco
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
vendor_cisco
CVE-2011-3274 Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
CVE-2011-3274: Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain. These vulnerabilities are: Crafted IPv6 Packet May Cause MPLS-Configured Device to Reload ICMPv6 Packet May Cause MPLS-Configured Device to Reload Cisco has released software updates that address these vulnerabilities.
Bug IDs: CSCtj30155, CSCto07919, CSCto07919, CSCtj30155
Suricata
ET WEB_SPECIFIC_APPS ZOHO ManageEngine ADSelfService Employee Search XSS Attempt
suricata·2011-06-09
CVE-2010-3274 ET WEB_SPECIFIC_APPS ZOHO ManageEngine ADSelfService Employee Search XSS Attempt
ET WEB_SPECIFIC_APPS ZOHO ManageEngine ADSelfService Employee Search XSS Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS ZOHO ManageEngine ADSelfService Employee Search XSS Attempt"; flow:established,to_server; http.uri; content:"/EmployeeSearch"; nocase; fast_pattern; content:"actionId="; nocase; content:"searchString="; nocase; pcre:"/^.+(?:script|alert|onmouse[a-z]+|onkey[a-z]+|onload|onunload|ondragdrop|onblur|onfocus|onclick|ondblclick|onsubmit|onreset|onselect|onchange)/Ri"; reference:url,www.coresecurity.com/content/zoho-manageengine-vulnerabilities; reference:cve,2010-3274; classtype:web-application-attack; sid:2012980; rev:3; metadata:created_at 2011_06_09, cve CVE_2010_3274, signature_severity Major, updated_at 2020_04_20;)
No public exploits indexed.
No writeups or analysis indexed.
2011-10-03
Published