Vulnerability Description
Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS after 12.3(2), 12.3(3)B, and 12.3(2)T and other products, allows remote attackers to cause a denial of service by sending a "spoofed neighbor announcement" with (1) mismatched k values or (2) "goodbye message" Type-Length-Value (TLV).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Extended Interior Gateway Routing Protocol | Extended Interior Gateway Routing Protocol | 1.2 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040330.htmlVendor Advisory
- http://marc.info/?l=full-disclosure&m=113504451523186&w=2
- http://securitytracker.com/id?1015382
- http://www.securityfocus.com/archive/1/419898/100/0/threaded
- http://www.securityfocus.com/bid/15978
- http://www.vupen.com/english/advisories/2005/3008
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040330.htmlVendor Advisory
- http://marc.info/?l=full-disclosure&m=113504451523186&w=2
- http://securitytracker.com/id?1015382
- http://www.securityfocus.com/archive/1/419898/100/0/threaded
- http://www.securityfocus.com/bid/15978
- http://www.vupen.com/english/advisories/2005/3008
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2005-4436?
CVE-2005-4436 is a vulnerability with a CVSS score of 7.8 (HIGH). Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS after 12.3(2), 12.3(3)B, and 12.3(2)T and other products, allows remote attackers to cause a denial of service by se...
How severe is CVE-2005-4436?
CVE-2005-4436 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4436?
Check the references section above for vendor advisories and patch information. Affected products include: Extended Interior Gateway Routing Protocol Extended Interior Gateway Routing Protocol.