Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
BID:29791
Info
Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
| Bugtraq ID: | 29791 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-2060 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2008 12:00AM |
| Updated: | Jun 20 2008 12:01AM |
| Credit: | HD Moore of BreakingPoint Systems |
| Vulnerable: |
Cisco IPS 4270 Sensor 0 Cisco IPS 4260 Sensor 0 Cisco IPS 4255 Sensor 0 Cisco IPS 4250XL Sensor 0 Cisco IPS 4250TX Sensor 0 Cisco IPS 4250SX Sensor 0 Cisco IPS 4250 Sensor 0 Cisco IPS 4240 Sensor 0 Cisco IPS 4235 Sensor 0 Cisco Intrusion Prevention System 5.0 (3) Cisco Intrusion Prevention System 5.0 (2) Cisco Intrusion Prevention System 5.0 (1) Cisco Intrusion Prevention System 6.0(4a)E1 Cisco Intrusion Prevention System 5.1(p1) Cisco Intrusion Prevention System 5.1(2) Cisco Intrusion Prevention System 5.1(1e) Cisco Intrusion Prevention System 5.1(1d) Cisco Intrusion Prevention System 5.1(1c) Cisco Intrusion Prevention System 5.1(1b) Cisco Intrusion Prevention System 5.1(1b) Cisco Intrusion Prevention System 5.1(1) Cisco Intrusion Prevention System 5.1 (1a) Cisco Intrusion Prevention System 5.0(6p2) Cisco Intrusion Prevention System 5.0(6p1) |
| Not Vulnerable: |
Cisco Intrusion Prevention System 6.0(5)E2 Cisco Intrusion Prevention System 5.1(8)E2 |
Discussion
Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
Cisco Intrustion Prevention System (IPS) platforms are prone to a denial-of-service vulnerability when handling jumbo Ethernet frames.
An attacker can exploit this issue to cause a kernel panic and deny service for legitimate users.
Versions prior to Cisco Intrustion Prevention System 5.1(8)E2 and 6.0(5)E2 are vulnerable.
NOTE: This issue affects only platforms that contain gigabit network interfaces and are deployed in inline mode.
Cisco Intrustion Prevention System (IPS) platforms are prone to a denial-of-service vulnerability when handling jumbo Ethernet frames.
An attacker can exploit this issue to cause a kernel panic and deny service for legitimate users.
Versions prior to Cisco Intrustion Prevention System 5.1(8)E2 and 6.0(5)E2 are vulnerable.
NOTE: This issue affects only platforms that contain gigabit network interfaces and are deployed in inline mode.
Exploit / POC
Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
Solution:
The vendor released an advisory and states that fixes will be available on June 20, 2008. Please see the referenced advisory for more information.
Solution:
The vendor released an advisory and states that fixes will be available on June 20, 2008. Please see the referenced advisory for more information.
References
Cisco Intrustion Prevention System (IPS) Platforms Inline Mode Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Jumbo/Giant Frame Support on Catalyst Switches Configuration Example (Cisco)
- Cisco Security Advisory: Cisco Intrusion Prevention System Jumbo Frame Denial of (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco Intrusion Prevention System Jumbo Frame Denial of (Cisco)