7.8

CVE-2008-3810

Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka CSCsg22426, a different vulnerability than CVE-2008-3811.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Version12.4md
CiscoIos Version12.4mr
CiscoIos Version12.4sw
CiscoIos Version12.4t
CiscoIos Version12.4xc
CiscoIos Version12.4xe
CiscoIos Version12.4xf
CiscoIos Version12.4xg
CiscoIos Version12.4xj
CiscoIos Version12.4xk
CiscoIos Version12.4xl
CiscoIos Version12.4xm
CiscoIos Version12.4xn
CiscoIos Version12.4xp
CiscoIos Version12.4xt
CiscoIos Version12.4xv
CiscoIos Version12.4xw
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.817
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.