First published: Mon Oct 03 2011(Updated: )
The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =3.1.0sg | |
Cisco IOS XE Web UI | =3.1.1sg | |
Cisco IOS | >=15.0<=15.1 | |
Cisco IOS | >=12.1<=12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3279 has been classified as a severity of high, as it can lead to a denial of service by device reload.
To mitigate CVE-2011-3279, upgrade to a version of Cisco IOS or IOS XE that is not vulnerable, specifically versions above 15.1 or 12.4.
CVE-2011-3279 affects Cisco IOS versions 12.1 to 12.4 and 15.0 to 15.1, as well as certain 3.1.xSG versions of IOS XE.
Yes, CVE-2011-3279 can be exploited remotely by sending a malformed SIP packet to UDP port 5060.
Exploitation of CVE-2011-3279 can cause a denial of service, resulting in device reload and potential network downtime.