CVE-2008-3803

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/09/2008
Last modified:
09/04/2025

Description

A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios:12.0s:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:12.0sx:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:12.0sz:*:*:*:*:*:*:*