CVE-2011-4007: Input Validation
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4007?
CVE-2011-4007 is classified as a high severity vulnerability due to its potential to cause a denial of service by crashing affected Cisco devices.
How do I fix CVE-2011-4007?
To remediate CVE-2011-4007, you should update affected Cisco IOS and IOS XE software to the latest patched versions provided by Cisco.
Which devices are affected by CVE-2011-4007?
CVE-2011-4007 affects Cisco IOS version 15.0 and 15.1 as well as IOS XE versions 3.1.0SG through 3.5.0S.
What is the impact of the vulnerability identified by CVE-2011-4007?
The impact of CVE-2011-4007 is that remote attackers can exploit this vulnerability to cause a denial of service through crafted network traffic.
What command triggers the vulnerability CVE-2011-4007?
The vulnerability CVE-2011-4007 is triggered by the improper handling of the "set mpls experimental imposition" command in the affected software.