CVE-2012-0382
published 2012-03-29CVE-2012-0382: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.85%
89.0th percentile
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.
Affected
759 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vqm-f884-p772: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-04
CVE-2012-0382 [HIGH] CWE-400 GHSA-5vqm-f884-p772: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.
Cisco
Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
vendor_cisco·2012-03-28·CVSS 7.1
CVE-2012-0382 [HIGH] Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
A vulnerability in the Multicast Source Discovery Protocol (MSDP) implementation of Cisco IOS Software and Cisco IOS XE Software could allow a remote, unauthenticated attacker to cause a reload of an affected device. Repeated attempts to exploit this vulnerability could result in a sustained denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-msdp
Note: The March 28, 2012, Cisco IOS Software Security Advisory bundled publication includes nine Cisco Security Advisori
Cisco
Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
vendor_cisco
CVE-2012-0382 Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
CVE-2012-0382: Cisco IOS Software Multicast Source Discovery Protocol Vulnerability
A vulnerability in the Multicast Source Discovery Protocol (MSDP) implementation of Cisco IOS Software and Cisco IOS XE Software could allow a remote, unauthenticated attacker to cause a reload of an affected device. Repeated attempts to exploit this vulnerability could result in a sustained denial of service (DoS) condition. Cisco has released software updates that address this vulnerability.
Bug IDs: CSCtr28857, CSCtr28857, CSCts38429
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80693http://secunia.com/advisories/48630http://secunia.com/advisories/48633http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-msdphttp://www.securityfocus.com/bid/52759http://www.securitytracker.com/id?1026868https://exchange.xforce.ibmcloud.com/vulnerabilities/74431http://osvdb.org/80693http://secunia.com/advisories/48630http://secunia.com/advisories/48633http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-msdphttp://www.securityfocus.com/bid/52759http://www.securitytracker.com/id?1026868https://exchange.xforce.ibmcloud.com/vulnerabilities/74431
2012-03-29
Published