CVE-2005-4440

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2005
Last modified:
03/04/2025

Description

The 802.1q VLAN protocol allows remote attackers to bypass network segmentation and spoof VLAN traffic via a message with two 802.1q tags, which causes the second tag to be redirected from a downstream switch after the first tag has been stripped, as demonstrated by Yersinia, aka "double-tagging VLAN jumping attack."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vlan_protocol:vlan_protocol:802.1q:*:*:*:*:*:*:*