First published: Thu Apr 24 2014(Updated: )
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | <=3.7s\(.1\) | |
Cisco IOS XE | =3.6.0s | |
Cisco IOS XE | =3.6.1s | |
Cisco IOS XE | =3.6.2s | |
Cisco IOS XE | =3.6s\(.0\) | |
Cisco IOS XE | =3.6s\(.1\) | |
Cisco IOS XE | =3.6s\(.2\) | |
Cisco IOS XE | =3.7.0s | |
Cisco IOS XE | =3.7.1s | |
Cisco IOS XE | =3.7.2s | |
Cisco IOS XE | =3.7s\(.0\) | |
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 | ||
Cisco ASR 1023 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5723 has a severity rating that indicates it can lead to a denial of service (DoS) condition.
To fix CVE-2012-5723, upgrade Cisco ASR 1000 devices to the software version 3.8S or later.
CVE-2012-5723 affects Cisco ASR 1000 devices running certain versions of Cisco IOS XE prior to 3.8S.
CVE-2012-5723 is associated with remote denial of service attacks using crafted broadcast or multicast ICMP packets.
Disabling BDI routing can serve as a temporary workaround for CVE-2012-5723.