First published: Tue Dec 31 2002(Updated: )
Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Extended Interior Gateway Routing Protocol Extended Interior Gateway Routing Protocol | =1.2 | |
Cisco IOS | =11.3 | |
Cisco IOS | =12.1 | |
Cisco IOS | =12.2 | |
Cisco IOS | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2208 has a high severity rating due to its potential to cause denial of service by flooding the network.
To fix CVE-2002-2208, update your Cisco IOS to a version above 12.2 which addresses this vulnerability.
CVE-2002-2208 affects specific versions of Cisco IOS from 11.3 to 12.2 as well as the Extended Interior Gateway Routing Protocol.
CVE-2002-2208 is associated with a denial of service attack that can be executed by sending spoofed EIGRP neighbor announcements.
The impact of CVE-2002-2208 on network performance can be severe, leading to an ARP storm that overwhelms the local network.