Vulnerability Description
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.0 |
| Cisco | Ios Xe | >= 2.1.0, <= 2.6.2 |
Related Weaknesses (CWE)
References
- http://osvdb.org/80693Broken Link
- http://secunia.com/advisories/48630Not Applicable
- http://secunia.com/advisories/48633Not Applicable
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/52759Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026868Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74431Third Party AdvisoryVDB Entry
- http://osvdb.org/80693Broken Link
- http://secunia.com/advisories/48630Not Applicable
- http://secunia.com/advisories/48633Not Applicable
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/52759Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026868Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74431Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-0382?
CVE-2012-0382 is a vulnerability with a CVSS score of 7.5 (HIGH). The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1...
How severe is CVE-2012-0382?
CVE-2012-0382 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0382?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Ios Xe.