5

CVE-2007-4430

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command.  NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Cli
Cisco ≫ Cbos
Cisco ≫ Cbos Version 12.1
Cisco ≫ Cbos Version 12.2
Cisco ≫ Ids
Cisco ≫ Ios Version 10.0
Cisco ≫ Ios Version 10.3
Cisco ≫ Ios Version 11.0
Cisco ≫ Ios Version 11.1
Cisco ≫ Ios Version 11.2
Cisco ≫ Ios Version 12.0
Cisco ≫ Ios Version 12.1
Cisco ≫ Ios Version 12.2
Cisco ≫ Ios Version 12.3
Cisco ≫ Ios Version 12.4
Cisco ≫ Ios Xr Version 2.0
Cisco ≫ Ios Xr Version 3.0
Cisco ≫ Ios Xr Version 3.1
Cisco ≫ Ios Xr Version 3.2
Cisco ≫ Ios Xr Version 3.3
Cisco ≫ Ios Xr Version 3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.28% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=WAN%2C%20Routing%20and%20Switching&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddf7bc9
http://secunia.com/advisories/26798
Vendor Advisory
http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html
http://www.heise-security.co.uk/news/94526/
http://www.securityfocus.com/bid/25352
http://www.securitytracker.com/id?1018685
http://www.vupen.com/english/advisories/2007/3136
Vendor Advisory
https://puck.nether.net/pipermail/cisco-nsp/2007-August/043002.html
https://puck.nether.net/pipermail/cisco-nsp/2007-August/043010.html