Vulnerability Description
The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many unicast EAPoL Protocol Data Units (PDUs), aka Bug ID CSCtq36336.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | >= 12.2, < 12.2\(33\)sxi7 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notRelease NotesVendor Advisory
- http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notRelease NotesVendor Advisory
FAQ
What is CVE-2011-2058?
CVE-2011-2058 is a vulnerability with a CVSS score of 7.5 (HIGH). The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of se...
How severe is CVE-2011-2058?
CVE-2011-2058 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2058?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios.