First published: Thu Apr 20 2006(Updated: )
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | =3.0.1 | |
Cisco IOS XRv 9000 | =3.1.0 | |
Cisco IOS XRv 9000 | =3.2 | |
Cisco IOS XRv 9000 | =3.2.1 | |
Cisco IOS XRv 9000 | =3.2.2 | |
Cisco IOS XRv 9000 | =3.2.3 | |
Cisco IOS XRv 9000 | =3.2.3 | |
Cisco IOS XRv 9000 | =3.2.4 | |
Cisco IOS XRv 9000 | =3.2.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1928 has a severity rating that typically indicates a high risk of denial of service due to potential crashes in affected Cisco devices.
Fixing CVE-2006-1928 involves upgrading Cisco IOS XR to a version that addresses this vulnerability, such as 3.2.4 or later.
CVE-2006-1928 affects Cisco IOS XR versions 3.0.1 through 3.2.3 on Cisco CRS-1 routers.
CVE-2006-1928 can lead to denial of service, causing Modular Services Cards to crash and impairing MPLS operations.
Yes, remote attackers can exploit CVE-2006-1928 by sending specially crafted MPLS packets to targeted Cisco devices.