CVE-2007-4291: High severity Cisco IOS vulnerability
Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474; and a malformed Real-time Transport Protocol (RTP) packet, which causes a device crash, as identified by (4) CSCse68138, related to VOIP RTP Lib, and (5) CSCse05642, related to I/O memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4291?
CVE-2007-4291 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2007-4291?
To mitigate CVE-2007-4291, it is recommended to update Cisco IOS to a version that is not affected by this vulnerability.
What are the symptoms of CVE-2007-4291 exploitation?
Exploitation of CVE-2007-4291 can lead to device hangs or crashes when processing malformed MGCP or H.323 packets.
Which versions of Cisco IOS are affected by CVE-2007-4291?
CVE-2007-4291 affects Cisco IOS versions 12.0 through 12.4.
Who should be concerned about CVE-2007-4291?
Network administrators using affected versions of Cisco IOS should be particularly concerned about CVE-2007-4291 due to its impact on device stability.