CVE-2012-4617
published 2012-09-27CVE-2012-4617: The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service…
PriorityP427high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.32%
81.6th percentile
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
vendor_cisco·2012-09-26·CVSS 7.1
CVE-2012-4617 [HIGH] CWE-399 Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
Cisco IOS Software contains a vulnerability in the Border Gateway Protocol (BGP) routing protocol feature.
The vulnerability can be triggered when the router receives a malformed attribute from a peer on an existing BGP session.
Successful exploitation of this vulnerability can cause all BGP sessions to reset. Repeated exploitation may result in an inability to route packets to BGP neighbors during reconvergence times.
Cisco has released software updates that address this vulnerability. There are no workarounds for this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-bgp
Note: The September 26, 2012
Cisco
Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
vendor_cisco
CVE-2012-4617 Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
CVE-2012-4617: Cisco IOS Software Malformed Border Gateway Protocol Attribute Vulnerability
Cisco IOS Software contains a vulnerability in the Border Gateway Protocol (BGP) routing protocol feature. The vulnerability can be triggered when the router receives a malformed attribute from a peer on an existing BGP session. Successful exploitation of this vulnerability can cause all BGP sessions to reset. Repeated exploitation may result in an inability to route packets to BGP neighbors during reconvergence times. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCtt35379, CSCty58300, CSCtz62914, CSCtt35379, CSCty58300
GHSA
GHSA-gmvh-96pj-qpf9: The BGP implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2012-4617 [HIGH] CWE-20 GHSA-gmvh-96pj-qpf9: The BGP implementation in Cisco IOS 15
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-bgphttp://www.securityfocus.com/bid/55694http://www.securitytracker.com/id?1027576http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-bgphttp://www.securityfocus.com/bid/55694http://www.securitytracker.com/id?1027576
2012-09-27
Published