Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
BID:22211
Info
Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
| Bugtraq ID: | 22211 |
| Class: | Design Error |
| CVE: |
CVE-2007-0480 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2007 12:00AM |
| Updated: | Jan 12 2009 02:02PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco IOS XR 3.3 Cisco IOS XR 3.2.50 Cisco IOS XR 3.2.4 Cisco IOS XR 3.2.3 Cisco IOS XR 3.2.2 Cisco IOS XR 3.2.1 Cisco IOS XR 3.2 Cisco IOS XR 3.1 .0 Cisco IOS XR 3.0.1 Cisco IOS XR 2.0 Cisco IOS XR Cisco IOS 12.2 12.2XU Cisco IOS 12.0.19 Cisco IOS 12.0.7 Cisco IOS 12.0.6 Cisco IOS 12.0.5 Cisco IOS 12.0.4 T Cisco IOS 12.0.4 S Cisco IOS 12.0.4 Cisco IOS 12.0.3 T2 Cisco IOS 12.0.3 Cisco IOS 12.0.2 XG Cisco IOS 12.0.2 XF Cisco IOS 12.0.2 XD Cisco IOS 12.0.2 XC Cisco IOS 12.0.2 Cisco IOS 12.0.1 XE Cisco IOS 12.0.1 XB Cisco IOS 12.0.1 XA3 Cisco IOS 12.0.1 W Cisco IOS 12.0.1 Cisco IOS 12.4XT Cisco IOS 12.4XP Cisco IOS 12.4XJ Cisco IOS 12.4XG Cisco IOS 12.4XE Cisco IOS 12.4XD Cisco IOS 12.4XC Cisco IOS 12.4XB Cisco IOS 12.4XA Cisco IOS 12.4T Cisco IOS 12.4SW Cisco IOS 12.4MR Cisco IOS 12.4(9)T Cisco IOS 12.4(8) Cisco IOS 12.4(7a) Cisco IOS 12.4(7) Cisco IOS 12.4(6)T1 Cisco IOS 12.4(6)T Cisco IOS 12.4(5b) Cisco IOS 12.4(5) Cisco IOS 12.4(4)T2 Cisco IOS 12.4(4)T2 Cisco IOS 12.4(4)T Cisco IOS 12.4(4)MR Cisco IOS 12.4(4)MR Cisco IOS 12.4(3d) Cisco IOS 12.4(3d) Cisco IOS 12.4(3b) Cisco IOS 12.4(3a) Cisco IOS 12.4(3)T2 Cisco IOS 12.4(3) Cisco IOS 12.4(3) Cisco IOS 12.4(2)XB2 Cisco IOS 12.4(2)XB Cisco IOS 12.4(2)XA Cisco IOS 12.4(2)T4 Cisco IOS 12.4(2)T4 Cisco IOS 12.4(2)T3 Cisco IOS 12.4(2)T2 Cisco IOS 12.4(2)T1 Cisco IOS 12.4(2)T Cisco IOS 12.4(2)MR1 Cisco IOS 12.4(2)MR Cisco IOS 12.4(1c) Cisco IOS 12.4(1b) Cisco IOS 12.4(1) Cisco IOS 12.4(1) Cisco IOS 12.4 Cisco IOS 12.4 Cisco IOS 12.3YZ Cisco IOS 12.3YX Cisco IOS 12.3YW Cisco IOS 12.3YU Cisco IOS 12.3YT Cisco IOS 12.3YS Cisco IOS 12.3YR Cisco IOS 12.3YQ Cisco IOS 12.3YN Cisco IOS 12.3YM Cisco IOS 12.3YL Cisco IOS 12.3YK Cisco IOS 12.3YJ Cisco IOS 12.3YI Cisco IOS 12.3YH Cisco IOS 12.3YG Cisco IOS 12.3YF Cisco IOS 12.3YE Cisco IOS 12.3YD Cisco IOS 12.3YC Cisco IOS 12.3YB Cisco IOS 12.3YA Cisco IOS 12.3XZ Cisco IOS 12.3XY Cisco IOS 12.3XX Cisco IOS 12.3XW Cisco IOS 12.3XV Cisco IOS 12.3XU Cisco IOS 12.3XT Cisco IOS 12.3XS Cisco IOS 12.3XR Cisco IOS 12.3XQ Cisco IOS 12.3XN Cisco IOS 12.3XM Cisco IOS 12.3XL Cisco IOS 12.3XK Cisco IOS 12.3XJ Cisco IOS 12.3XI Cisco IOS 12.3XH Cisco IOS 12.3XG Cisco IOS 12.3XF Cisco IOS 12.3XE Cisco IOS 12.3XD Cisco IOS 12.3XC Cisco IOS 12.3XB Cisco IOS 12.3XA Cisco IOS 12.3TPC Cisco IOS 12.3T Cisco IOS 12.3JX Cisco IOS 12.3JL Cisco IOS 12.3JK Cisco IOS 12.3JEB Cisco IOS 12.3JEA Cisco IOS 12.3JA Cisco IOS 12.3BW Cisco IOS 12.3BC Cisco IOS 12.3B Cisco IOS 12.3(8)JK Cisco IOS 12.3(8)JA1 Cisco IOS 12.3(8)JA Cisco IOS 12.3(5) Cisco IOS 12.3(4)XH Cisco IOS 12.3(4)XG5 Cisco IOS 12.3(4)XG4 Cisco IOS 12.3(4)XG2 Cisco IOS 12.3(4)XG1 Cisco IOS 12.3(4)XE4 Cisco IOS 12.3(4)XD2 Cisco IOS 12.3(4)XD1 Cisco IOS 12.3(4)XD Cisco IOS 12.3(4)TPC11a Cisco IOS 12.3(4)T8 Cisco IOS 12.3(4)T4 Cisco IOS 12.3(4)T3 Cisco IOS 12.3(4)T2 Cisco IOS 12.3(4)T13 Cisco IOS 12.3(4)T1 Cisco IOS 12.3(4)T1 Cisco IOS 12.3(4)T Cisco IOS 12.3(4)T Cisco IOS 12.3(4)JA1 Cisco IOS 12.3(4)JA Cisco IOS 12.3(4)JA Cisco IOS 12.3(4)EO1 Cisco IOS 12.3(3i) Cisco IOS 12.3(3h) Cisco IOS 12.3(3e) Cisco IOS 12.3(2)XE4 Cisco IOS 12.3(2)XE3 Cisco IOS 12.3(2)XC4 Cisco IOS 12.3(2)XC3 Cisco IOS 12.3(2)XC3 Cisco IOS 12.3(2)XC2 Cisco IOS 12.3(2)XC1 Cisco IOS 12.3(2)XA5 Cisco IOS 12.3(2)XA4 Cisco IOS 12.3(2)T8 Cisco IOS 12.3(2)T3 Cisco IOS 12.3(2)JK1 Cisco IOS 12.3(2)JK Cisco IOS 12.3(2)JA5 Cisco IOS 12.3(2)JA Cisco IOS 12.3(1a) Cisco IOS 12.3(16) Cisco IOS 12.3(15b) Cisco IOS 12.3(15) Cisco IOS 12.3(14)YX Cisco IOS 12.3(14)YU1 Cisco IOS 12.3(14)YU Cisco IOS 12.3(14)YT1 Cisco IOS 12.3(14)YT Cisco IOS 12.3(14)YQ8 Cisco IOS 12.3(14)YQ4 Cisco IOS 12.3(14)YQ3 Cisco IOS 12.3(14)YQ1 Cisco IOS 12.3(14)YQ Cisco IOS 12.3(14)YM8 Cisco IOS 12.3(14)YM4 Cisco IOS 12.3(14)YG5 Cisco IOS 12.3(14)T8 Cisco IOS 12.3(14)T7 Cisco IOS 12.3(14)T7 Cisco IOS 12.3(14)T5 Cisco IOS 12.3(14)T4 Cisco IOS 12.3(14)T2 Cisco IOS 12.3(14)T Cisco IOS 12.3(13b) Cisco IOS 12.3(13a)BC1 Cisco IOS 12.3(13a)BC Cisco IOS 12.3(13a)BC Cisco IOS 12.3(13a) Cisco IOS 12.3(13) Cisco IOS 12.3(12e) Cisco IOS 12.3(12b) Cisco IOS 12.3(12) Cisco IOS 12.3(11)YW Cisco IOS 12.3(11)YS1 Cisco IOS 12.3(11)YS Cisco IOS 12.3(11)YR Cisco IOS 12.3(11)YN Cisco IOS 12.3(11)YL Cisco IOS 12.3(11)YK2 Cisco IOS 12.3(11)YK1 Cisco IOS 12.3(11)YK Cisco IOS 12.3(11)YJ Cisco IOS 12.3(11)YJ Cisco IOS 12.3(11)YF4 Cisco IOS 12.3(11)YF3 Cisco IOS 12.3(11)YF2 Cisco IOS 12.3(11)YF Cisco IOS 12.3(11)XL3 Cisco IOS 12.3(11)XL Cisco IOS 12.3(11)T8 Cisco IOS 12.3(11)T6 Cisco IOS 12.3(11)T5 Cisco IOS 12.3(11)T4 Cisco IOS 12.3(11)T Cisco IOS 12.3(11) Cisco IOS 12.3(10e) Cisco IOS 12.3(10d) Cisco IOS 12.3(10c) Cisco IOS 12.3(10) Cisco IOS 12.3 Cisco IOS 12.3 Cisco IOS 12.2ZQ Cisco IOS 12.2ZP Cisco IOS 12.2ZO Cisco IOS 12.2ZN Cisco IOS 12.2ZL Cisco IOS 12.2ZL Cisco IOS 12.2ZK Cisco IOS 12.2ZJ Cisco IOS 12.2ZJ Cisco IOS 12.2ZJ Cisco IOS 12.2ZI Cisco IOS 12.2ZH Cisco IOS 12.2ZH Cisco IOS 12.2ZG Cisco IOS 12.2ZG Cisco IOS 12.2ZF Cisco IOS 12.2ZF Cisco IOS 12.2ZE Cisco IOS 12.2ZE Cisco IOS 12.2ZD Cisco IOS 12.2ZD Cisco IOS 12.2ZC Cisco IOS 12.2ZC Cisco IOS 12.2ZB Cisco IOS 12.2ZB Cisco IOS 12.2ZA Cisco IOS 12.2ZA Cisco IOS 12.2YZ Cisco IOS 12.2YZ Cisco IOS 12.2YY Cisco IOS 12.2YY Cisco IOS 12.2YX Cisco IOS 12.2YX Cisco IOS 12.2YW Cisco IOS 12.2YW Cisco IOS 12.2YW Cisco IOS 12.2YV Cisco IOS 12.2YV Cisco IOS 12.2YU Cisco IOS 12.2YU Cisco IOS 12.2YT Cisco IOS 12.2YT Cisco IOS 12.2YS Cisco IOS 12.2YS Cisco IOS 12.2YS Cisco IOS 12.2YR Cisco IOS 12.2YR Cisco IOS 12.2YQ Cisco IOS 12.2YQ Cisco IOS 12.2YP Cisco IOS 12.2YP Cisco IOS 12.2YO Cisco IOS 12.2YO Cisco IOS 12.2YN Cisco IOS 12.2YN Cisco IOS 12.2YM Cisco IOS 12.2YM Cisco IOS 12.2YL Cisco IOS 12.2YL Cisco IOS 12.2YK Cisco IOS 12.2YK Cisco IOS 12.2YJ Cisco IOS 12.2YH Cisco IOS 12.2YG Cisco IOS 12.2YF Cisco IOS 12.2YE Cisco IOS 12.2YD Cisco IOS 12.2YC Cisco IOS 12.2YB Cisco IOS 12.2YA Cisco IOS 12.2XZ Cisco IOS 12.2XW Cisco IOS 12.2XV Cisco IOS 12.2XU Cisco IOS 12.2XT Cisco IOS 12.2XS Cisco IOS 12.2XR Cisco IOS 12.2XQ Cisco IOS 12.2XQ Cisco IOS 12.2XN Cisco IOS 12.2XM Cisco IOS 12.2XL Cisco IOS 12.2XK Cisco IOS 12.2XK Cisco IOS 12.2XK Cisco IOS 12.2XJ Cisco IOS 12.2XJ Cisco IOS 12.2XI Cisco IOS 12.2XH Cisco IOS 12.2XG Cisco IOS 12.2XF Cisco IOS 12.2XE Cisco IOS 12.2XD Cisco IOS 12.2XC Cisco IOS 12.2XB15 Cisco IOS 12.2XB Cisco IOS 12.2XA Cisco IOS 12.2TPC Cisco IOS 12.2T Cisco IOS 12.2SZ Cisco IOS 12.2SZ Cisco IOS 12.2SY Cisco IOS 12.2SY Cisco IOS 12.2SXF Cisco IOS 12.2SXE Cisco IOS 12.2SXE Cisco IOS 12.2SXD Cisco IOS 12.2SXB Cisco IOS 12.2SXA Cisco IOS 12.2SX Cisco IOS 12.2SW Cisco IOS 12.2SV Cisco IOS 12.2SU Cisco IOS 12.2SRB Cisco IOS 12.2SRA Cisco IOS 12.2SO Cisco IOS 12.2SH Cisco IOS 12.2SGB Cisco IOS 12.2SGA Cisco IOS 12.2SG Cisco IOS 12.2SEG Cisco IOS 12.2SEF Cisco IOS 12.2SEF Cisco IOS 12.2SEE Cisco IOS 12.2SEE Cisco IOS 12.2SED Cisco IOS 12.2SED Cisco IOS 12.2SEC Cisco IOS 12.2SEB Cisco IOS 12.2SEA Cisco IOS 12.2SE Cisco IOS 12.2SBC Cisco IOS 12.2SB Cisco IOS 12.2SA Cisco IOS 12.2S Cisco IOS 12.2PI Cisco IOS 12.2PB Cisco IOS 12.2MX Cisco IOS 12.2MX Cisco IOS 12.2MC Cisco IOS 12.2MC Cisco IOS 12.2MB Cisco IOS 12.2JK Cisco IOS 12.2JA Cisco IOS 12.2JA Cisco IOS 12.2JA Cisco IOS 12.2IXA Cisco IOS 12.2FY Cisco IOS 12.2FX Cisco IOS 12.2EZ Cisco IOS 12.2EY Cisco IOS 12.2EX Cisco IOS 12.2EWA Cisco IOS 12.2EW Cisco IOS 12.2EU Cisco IOS 12.2DX Cisco IOS 12.2DX Cisco IOS 12.2DD Cisco IOS 12.2DA Cisco IOS 12.2CZ Cisco IOS 12.2CY Cisco IOS 12.2CY Cisco IOS 12.2CX Cisco IOS 12.2CX Cisco IOS 12.2CX Cisco IOS 12.2BZ Cisco IOS 12.2BY Cisco IOS 12.2BX Cisco IOS 12.2BW Cisco IOS 12.2BW Cisco IOS 12.2BC Cisco IOS 12.2B Cisco IOS 12.2 Cisco IOS 12.1YJ Cisco IOS 12.1YI Cisco IOS 12.1YH Cisco IOS 12.1YF Cisco IOS 12.1YE Cisco IOS 12.1YD Cisco IOS 12.1YC Cisco IOS 12.1YB Cisco IOS 12.1YA Cisco IOS 12.1XZ Cisco IOS 12.1XY Cisco IOS 12.1XX Cisco IOS 12.1XW Cisco IOS 12.1XV Cisco IOS 12.1XU Cisco IOS 12.1XT Cisco IOS 12.1XS Cisco IOS 12.1XR Cisco IOS 12.1XQ Cisco IOS 12.1XP Cisco IOS 12.1XM Cisco IOS 12.1XL Cisco IOS 12.1XK Cisco IOS 12.1XJ Cisco IOS 12.1XI Cisco IOS 12.1XH Cisco IOS 12.1XG Cisco IOS 12.1XF Cisco IOS 12.1XE Cisco IOS 12.1XD Cisco IOS 12.1XC Cisco IOS 12.1XB Cisco IOS 12.1XA Cisco IOS 12.1X(l) Cisco IOS 12.1T Cisco IOS 12.1T Cisco IOS 12.1SEC Cisco IOS 12.1M Cisco IOS 12.1GB Cisco IOS 12.1GA Cisco IOS 12.1EZ Cisco IOS 12.1EY Cisco IOS 12.1EX Cisco IOS 12.1EW Cisco IOS 12.1EV Cisco IOS 12.1EU Cisco IOS 12.1EO Cisco IOS 12.1EC Cisco IOS 12.1EB Cisco IOS 12.1EB Cisco IOS 12.1EA Cisco IOS 12.1E Cisco IOS 12.1DC Cisco IOS 12.1DB Cisco IOS 12.1DA Cisco IOS 12.1CX Cisco IOS 12.1AZ Cisco IOS 12.1AY Cisco IOS 12.1AY Cisco IOS 12.1AX Cisco IOS 12.1AX Cisco IOS 12.1AA Cisco IOS 12.10S Cisco IOS 12.0XW Cisco IOS 12.0XV Cisco IOS 12.0XU Cisco IOS 12.0XT Cisco IOS 12.0XS Cisco IOS 12.0XR Cisco IOS 12.0XQ Cisco IOS 12.0XP Cisco IOS 12.0XN Cisco IOS 12.0XM Cisco IOS 12.0XL Cisco IOS 12.0XK Cisco IOS 12.0XJ Cisco IOS 12.0XI Cisco IOS 12.0XH Cisco IOS 12.0XG Cisco IOS 12.0XF Cisco IOS 12.0XE Cisco IOS 12.0XD Cisco IOS 12.0XC Cisco IOS 12.0XB Cisco IOS 12.0XA Cisco IOS 12.0WX Cisco IOS 12.0WT Cisco IOS 12.0WC Cisco IOS 12.0WC Cisco IOS 12.0WC Cisco IOS 12.0W5 Cisco IOS 12.0T Cisco IOS 12.0T Cisco IOS 12.0SZ Cisco IOS 12.0SZ Cisco IOS 12.0SY Cisco IOS 12.0SX Cisco IOS 12.0SV Cisco IOS 12.0ST Cisco IOS 12.0SP Cisco IOS 12.0SL Cisco IOS 12.0SC Cisco IOS 12.0S Cisco IOS 12.0EV Cisco IOS 12.0DC Cisco IOS 12.0DB Cisco IOS 12.0DA Cisco IOS 12.0 Cisco IOS 0 |
| Not Vulnerable: | |
Discussion
Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
Multiple Cisco switches and routers running Cisco IOS and Cisco IOS XR are prone to multiple remote code-execution vulnerabilities. These issues occur because the devices fail to handle specially crafted network packets.
An attacker can exploit these issues to execute arbitrary code within the context of the affected device. Failed exploit attempts will result in a denial of service.
These issues affect only devices that are configured to handle Internet Protocol version 4 (IPv4) packets. These issues do not affect devices that are configured to handle only Internet Protocol version 6 (IPV6) packets.
These issues are being tracked by Cisco Bug IDs CSCeh52410 and CSCec71950.
Multiple Cisco switches and routers running Cisco IOS and Cisco IOS XR are prone to multiple remote code-execution vulnerabilities. These issues occur because the devices fail to handle specially crafted network packets.
An attacker can exploit these issues to execute arbitrary code within the context of the affected device. Failed exploit attempts will result in a denial of service.
These issues affect only devices that are configured to handle Internet Protocol version 4 (IPv4) packets. These issues do not affect devices that are configured to handle only Internet Protocol version 6 (IPV6) packets.
These issues are being tracked by Cisco Bug IDs CSCeh52410 and CSCec71950.
Exploit / POC
Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
An exploit for this issue was demonstrated at the 2008 Chaos Communication Congress; please see the references for more information. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit for this issue was demonstrated at the 2008 Chaos Communication Congress; please see the references for more information. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and fixes addressing this issue. Please see the referenced vendor advisory for details.
Solution:
The vendor released an advisory and fixes addressing this issue. Please see the referenced vendor advisory for details.
References
Cisco Multiple Devices Crafted IP Option Multiple Remote Code Execution Vulnerability
References:
References:
- Cisco Applied Intelligence Response: Identifying and Mitigating Exploitation of (Cisco )
- Cisco IOS Homepage (Cisco Systems)
- Release of the slides from the 25C3 presentation on Cisco IOS forensics and expl (Phenoelit)
- Cisco Security Advisory: Crafted IP Option Vulnerability (Cisco)
- Vulnerability Note VU#341288 - Cisco IOS fails to properly prcoess certain packe (US-CERT)