CVE-2011-3282
published 2011-10-03CVE-2011-3282: Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.84%
76.7th percentile
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCtj30155.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7vj-9gxx-w84g: Unspecified vulnerability in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2011-3282 [HIGH] GHSA-c7vj-9gxx-w84g: Unspecified vulnerability in Cisco IOS 12
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCtj30155.
Cisco
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
vendor_cisco·2011-09-28·CVSS 7.8
CVE-2011-3274 [HIGH] Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software is affected by two vulnerabilities that cause a
Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a
Multiprotocol Label Switching (MPLS) domain. These vulnerabilities are:
Crafted IPv6 Packet May Cause MPLS-Configured Device to Reload
ICMPv6 Packet May Cause MPLS-Configured Device to Reload
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate these vulnerabilities are available.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-ipv6mpls.
Note: The September 28, 2011, Cisco IOS Software
Security Advisory bundled publication includes ten C
Cisco
Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
vendor_cisco
CVE-2011-3282 Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
CVE-2011-3282: Cisco IOS Software IP Version 6 over Multiprotocol Label Switching Vulnerabilities
Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain. These vulnerabilities are: Crafted IPv6 Packet May Cause MPLS-Configured Device to Reload ICMPv6 Packet May Cause MPLS-Configured Device to Reload Cisco has released software updates that address these vulnerabilities.
Bug IDs: CSCtj30155, CSCto07919, CSCto07919, CSCtj30155
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-10-03
Published