First published: Wed May 02 2012(Updated: )
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =3.2.0sg | |
Cisco IOS XE | =3.5.0s | |
Cisco IOS XE | =3.4.1s | |
Cisco IOS | =15.1 | |
Cisco IOS XE | =3.3.3s | |
Cisco IOS XE | =3.3.1s | |
Cisco IOS XE | =3.2.0s | |
Cisco IOS XE | =3.3.2s | |
Cisco IOS | =15.0 | |
Cisco IOS XE | =3.2.1sg | |
Cisco IOS XE | =3.2.1s | |
Cisco IOS XE | =3.1.0sg | |
Cisco IOS XE | =3.1.2s | |
Cisco IOS XE | =3.4.0s | |
Cisco IOS XE | =3.1.1s | |
Cisco IOS XE | =3.2.2s | |
Cisco IOS XE | =3.1.0s | |
Cisco IOS XE | =3.1.4s | |
Cisco IOS XE | =3.3.0s | |
Cisco IOS XE | =3.1.3s | |
Cisco IOS XE | =3.1.1sg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4007 is classified as a high severity vulnerability due to its potential to cause a denial of service by crashing affected Cisco devices.
To remediate CVE-2011-4007, you should update affected Cisco IOS and IOS XE software to the latest patched versions provided by Cisco.
CVE-2011-4007 affects Cisco IOS version 15.0 and 15.1 as well as IOS XE versions 3.1.0SG through 3.5.0S.
The impact of CVE-2011-4007 is that remote attackers can exploit this vulnerability to cause a denial of service through crafted network traffic.
The vulnerability CVE-2011-4007 is triggered by the improper handling of the "set mpls experimental imposition" command in the affected software.