CVE-2011-3275: High severity cisco IOS vulnerability
Published Oct 3, 2011
·Updated
Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted SIP message, aka Bug ID CSCti48504.
Affected Software
17 affected components
cisco IOS=15.1
cisco IOS=15.0
cisco IOS=12.4
Cisco IOS XE=2.5.0
Cisco IOS XE=2.6.1
Cisco IOS XE=3.2.0s
Cisco IOS XE=2.5.1
Cisco IOS XE=2.6.2
Cisco IOS XE=2.6.0
Cisco IOS XE=3.2.1s
Cisco IOS XE=3.1.2s
Cisco IOS XE=3.1.1s
Cisco IOS XE=3.2.2s
Cisco IOS XE=3.1.0s
Cisco IOS XE=3.1.4s
Cisco IOS XE=2.5.2
Cisco IOS XE=3.1.3s
Event History
Oct 3, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3275?
CVE-2011-3275 is considered a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2011-3275?
To fix CVE-2011-3275, it is recommended to upgrade to the patched version of Cisco IOS or IOS XE provided by Cisco.
3
What devices are affected by CVE-2011-3275?
CVE-2011-3275 affects Cisco IOS versions 12.4, 15.0, 15.1 and IOS XE versions 2.5.x through 3.2.x.
4
Can CVE-2011-3275 be exploited remotely?
Yes, CVE-2011-3275 can be exploited remotely by sending a crafted SIP message to affected devices.
5
What are the symptoms of CVE-2011-3275 exploitation?
Exploitation of CVE-2011-3275 may lead to significant memory consumption and result in device unresponsiveness.