Multiple IOS IPS Vulnerabilities

high Nessus Plugin ID 49000

Language:

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

The Intrusion Prevention System (IPS) feature set of Cisco IOS contains several vulnerabilities. These include:

- Fragmented IP packets may be used to evade signature inspection. (CVE-2007-0917)

- IPS signatures utilizing the regular expression feature of the ATOMIC.TCP signature engine may cause a router to crash resulting in a denial of service. (CVE-2007-0918)

Solution

Apply the relevant patch referenced in Cisco Security Advisory cisco-sa-20070213-iosips.

See Also

http://www.nessus.org/u?644ae844

http://www.nessus.org/u?a7d0ea33

Plugin Details

Severity: High

ID: 49000

File Name: cisco-sa-20070213-iosipshttp.nasl

Version: 1.13

Type: local

Family: CISCO

Published: 9/1/2010

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: cpe:/o:cisco:ios

Required KB Items: Host/Cisco/IOS/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 2/13/2007

Vulnerability Publication Date: 2/13/2007

Reference Information

CVE: CVE-2007-0917, CVE-2007-0918

BID: 22549

CWE: 20

CISCO-SA: cisco-sa-20070213-iosips

CISCO-BUG-ID: CSCsa53334, CSCsg15598