CVE-2012-2488
published 2012-05-31CVE-2012-2488: Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage)…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.21%
80.7th percentile
Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | <= 4.2.0 | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5qh-vv4g-4g87: Cisco IOS XR before 4
ghsa_unreviewed·2022-05-17
CVE-2012-2488 [HIGH] CWE-20 GHSA-w5qh-vv4g-4g87: Cisco IOS XR before 4
Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593.
Cisco
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
vendor_cisco·2012-05-30·CVSS 7.8
CVE-2012-2488 [HIGH] Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software contains a vulnerability when handling crafted packets that may result in a denial of service condition. The vulnerability only exists on Cisco 9000 Series Aggregation Services Routers (ASR) Route Switch Processor (RSP-4G and RSP-8G), Route Switch Processor 440 (RSP440), and Cisco Carrier Routing System (CRS) Performance Route Processor (PRP). The vulnerability is a result of improper handling of crafted packets and could cause the route processor, which processes the packets, to be unable to transmit packets to the fabric.
Cisco has released software updates that address this vulnerability. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/C
Cisco
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
vendor_cisco
CVE-2012-2488 Cisco IOS XR Software Route Processor Denial of Service Vulnerability
CVE-2012-2488: Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software contains a vulnerability when handling crafted packets that may result in a denial of service condition. The vulnerability only exists on Cisco 9000 Series Aggregation Services Routers (ASR) Route Switch Processor (RSP-4G and RSP-8G), Route Switch Processor 440 (RSP440), and Cisco Carrier Routing System (CRS) Performance Route Processor (PRP). The vulnerability is a result of improper handling of crafted packets and could cause the route processor, which processes the packets, to be unable to transmit packets to the fabric. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/cen
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/49329http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120530-iosxrhttp://www.securityfocus.com/bid/53728http://www.securitytracker.com/id?1027104http://secunia.com/advisories/49329http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120530-iosxrhttp://www.securityfocus.com/bid/53728http://www.securitytracker.com/id?1027104
2012-05-31
Published