CVE-2012-4617
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
27/09/2012
Last modified:
11/04/2025
Description
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
Impact
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios:15.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:3.5.0s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:3.5.1s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:4.2.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-bgp
- http://www.securityfocus.com/bid/55694
- http://www.securitytracker.com/id?1027576=
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-bgp
- http://www.securityfocus.com/bid/55694
- http://www.securitytracker.com/id?1027576=



