Executive Summary

Summary
Title Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
Informations
Name cisco-sa-20100324-ldp First vendor Publication 2009-12-16
Vendor Cisco Last vendor Modification 2010-03-24
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A device running Cisco IOS® Software, Cisco IOS XE Software, or Cisco IOS XR Software is vulnerable to a remote denial of service (DoS) condition if it is configured for Multiprotocol Label Switching (MPLS) and has support for Label Distribution Protocol (LDP).

A crafted LDP UDP packet can cause an affected device running Cisco IOS Software or Cisco IOS XE Software to reload. On devices running affected versions of Cisco IOS XR Software, such packets can cause the device to restart the mpls_ldp process.

A system is vulnerable if configured with either LDP or Tag Distribution Protocol (TDP).

Cisco has released free software updates that address this vulnerability.

Workarounds that mitigate this vulnerability are available.

Original Source

Url : http://www.cisco.com/warp/public/707/cisco-sa-20100324-ldp.shtml

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 168
Os 3
Os 15

Open Source Vulnerability Database (OSVDB)

Id Description
63188 Cisco IOS Label Distribution Protocol (LDP) Hello Message Handling Remote DoS

Nessus® Vulnerability Scanner

Date Description
2013-12-14 Name : The remote device is missing a vendor-supplied security patch.
File : cisco-sa-20100324-ldp-iosxr.nasl - Type : ACT_GATHER_INFO
2010-09-01 Name : The remote device is missing a vendor-supplied security patch.
File : cisco-sa-20100324-ldphttp.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 10:21:58
  • Multiple Updates