Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

BID:19998

CVE-2006-4774 | CVE-2006-4775 | CVE-2006-4776 |

Info

Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

Bugtraq ID: 19998
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Sep 13 2006 12:00AM
Updated: Sep 14 2006 06:47PM
Credit: This vulnerability was reported by [email protected].
Vulnerable: Cisco IOS 12.1(19)
Cisco IOS 0
Cisco CatOS
Not Vulnerable:

Discussion

Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

Cisco IOS is prone to multiple vulnerabilities when handling VLAN Trunking Protocol (VTP) packets.

These issues include two denial-of-service vulnerabilities and a buffer-overflow vulnerability.

Attackers require access to trunk ports on affected devices for VTP packets to be accepted. Attackers may reportedly use the Dynamic Trunk Protocol (DTP) to become a trunking peer to gain required access.

By exploiting these issues, attackers may crash affected routers, cause further VTP packets to be ignored, or potentially execute arbitrary machine code in the context of affected devices.

Cisco IOS 12.1(19) is vulnerable to these issues; other versions are also likely affected.

Exploit / POC

Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

Solution:
Cisco BUG IDs CSCsd52629/CSCsd34759, CSCse40078/CSCse47765, and CSCsd34855/CSCei54611 contain information about fixes for these issues. Users of affected packages should contact the vendor for more information about obtaining and applying fixes.

References

Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report