Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

BID:7607

Info

Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

Bugtraq ID: 7607
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: May 15 2003 12:00AM
Updated: May 15 2003 12:00AM
Credit: This vulnerability was reported by the vendor.
Vulnerable: Cisco IOS 12.2YH
Cisco IOS 12.2YG
Cisco IOS 12.2YF
Cisco IOS 12.2YC
Cisco IOS 12.2YB
Cisco IOS 12.2YA
Cisco IOS 12.2XM
Cisco IOS 12.2XL
Cisco IOS 12.2XK
Cisco IOS 12.2XJ
Cisco IOS 12.2XI
Cisco IOS 12.2XH
Cisco IOS 12.2XE
Cisco IOS 12.2XD
Cisco IOS 12.2XC
Cisco IOS 12.2S
Cisco IOS 12.2MB
Cisco IOS 12.2DA
Cisco IOS 12.2BZ
Cisco IOS 12.2BY
Cisco IOS 12.2BC
Cisco IOS 12.2(7a)
Cisco IOS 12.2(7)DA
Cisco IOS 12.2(7)
Cisco IOS 12.2(4)B
Cisco IOS 12.2
Cisco IOS 12.1YC
Cisco IOS 12.1YB
Cisco IOS 12.1XG
Cisco IOS 12.1XF
Cisco IOS 12.1EY
Cisco IOS 12.1EX
Cisco IOS 12.1EW
Cisco IOS 12.1EC
Cisco IOS 12.1EA
Cisco IOS 12.1E
Cisco IOS 12.1(12b)
Cisco IOS 12.1(11b)
Cisco IOS 12.1(11)
Cisco IOS 12.1(10a)
Cisco IOS 12.1(10)EY
Cisco IOS 12.1(10)EX
Cisco IOS 12.1(10)E
Cisco IOS 12.1
Cisco IOS 12.0XE
Cisco IOS 12.0WC
Cisco IOS 12.0SY
Cisco IOS 12.0SX
Cisco IOS 12.0ST
Cisco IOS 12.0SP
Cisco IOS 12.0SL
Cisco IOS 12.0SC
Cisco IOS 12.0S
Cisco IOS 12.0(21)SX
Cisco IOS 12.0(21)ST
Cisco IOS 12.0(21)S
Cisco IOS 12.0(19)ST
Cisco IOS 12.0(19)S
Cisco IOS 12.0(18)S
Cisco IOS 12.0(17)S
Cisco 800
Cisco 7600
Cisco 7500
Cisco 7300
Cisco 7200
Cisco 7100
Cisco 7010
Cisco 7000
Cisco 6400 NSP
Cisco 6400 NRP
Cisco 6400
Cisco 6200
Cisco 4700
Cisco 4500
Cisco 4000
Cisco 3800
Cisco 3600
Cisco 3000
Cisco 2600
Cisco 2500
Cisco 1700
Cisco 1600
Cisco 1500
Cisco 1400
Cisco 12000
Cisco 10700
Cisco 1005
Cisco 1000
Not Vulnerable:

Discussion

Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

It has been reported that Cisco IOS is vulnerable to an issue in handling Service Assurance Agent (previously called Response Time Reporter, or RTR) packets. Because of this, a remote user may be able to cause the router to become unstable and crash.

Exploit / POC

Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

Solution:
Fixes are available. Affected users are advised to contact the vendor or authorized resellers for further information. See the advisory in the reference section for the vendor fix list.


Cisco IOS 12.0SY

Cisco IOS 12.2XC

Cisco IOS 12.0SC
  • Cisco IOS 12.1EC


Cisco IOS 12.2BZ

Cisco IOS 12.2DA

Cisco IOS 12.0SL
  • Cisco IOS 12.0S

  • Cisco IOS 12.0ST


Cisco IOS 12.1EX

Cisco IOS 12.1EW

Cisco IOS 12.2S

Cisco IOS 12.2YH

Cisco IOS 12.2YA

Cisco IOS 12.2MB

Cisco IOS 12.2YC

Cisco IOS 12.0ST
  • Cisco IOS 12.0(19)ST5

  • Cisco IOS 12.0(21)ST2


Cisco IOS 12.1
  • Cisco IOS 12.1(18)


Cisco IOS 12.2

Cisco IOS 12.0XE
  • Cisco IOS 12.2


Cisco IOS 12.1EC

Cisco IOS 12.1YC

Cisco IOS 12.1EA

Cisco IOS 12.1E

Cisco IOS 12.2YG

Cisco IOS 12.0S
  • Cisco IOS 12.0(21)S3


Cisco IOS 12.2XK

Cisco IOS 12.1YB

Cisco IOS 12.2(4)B

Cisco IOS 12.0WC

Cisco IOS 12.1XG

Cisco IOS 12.2XL

Cisco IOS 12.1XF
  • Cisco IOS 12.2

References

Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report