Vulnerability Description
Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Catalyst 6500 | All versions |
| Cisco | Catalyst 6500 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-X6380-Nam | 2.1\(2\) |
| Cisco | Catalyst 7600 | All versions |
| Cisco | Catalyst 7600 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-X6380-Nam | 2.1\(2\) |
| Cisco | Catos | 5.4\(1\) |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2007/Sep/0573.html
- http://secunia.com/advisories/26988
- http://securitytracker.com/id?1018742
- http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtmlPatch
- http://www.securityfocus.com/bid/25822Exploit
- http://www.securitytracker.com/id?1018743
- http://www.vupen.com/english/advisories/2007/3276
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36826
- http://seclists.org/fulldisclosure/2007/Sep/0573.html
- http://secunia.com/advisories/26988
- http://securitytracker.com/id?1018742
- http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtmlPatch
- http://www.securityfocus.com/bid/25822Exploit
- http://www.securitytracker.com/id?1018743
- http://www.vupen.com/english/advisories/2007/3276
FAQ
What is CVE-2007-5134?
CVE-2007-5134 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interf...
How severe is CVE-2007-5134?
CVE-2007-5134 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5134?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Catalyst 6500, Cisco Catalyst 6500 Ws-Svc-Nam-1, Cisco Catalyst 6500 Ws-Svc-Nam-2, Cisco Catalyst 6500 Ws-X6380-Nam, Cisco Catalyst 7600.