The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.
http://www.securityfocus.com/bid/4949
http://www.iss.net/security_center/static/9283.php
http://archives.neohapsis.com/archives/bugtraq/2002-06/0050.html
http://archives.neohapsis.com/archives/bugtraq/2002-06/0027.html