CVE-2007-0918

Cisco IOS - Denial of Service in ATOMIC.TCP Signature Engine

Title source: llm
STIX 2.1

Description

The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.

References (9)

Core 9
Core References
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/33053
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017631
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32474
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22549
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24142
Permissions Required, Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0597

Scores

EPSS 0.0311
EPSS Percentile 86.4%

Details

Status published
Products (25)
cisco/ios 12.3t
cisco/ios 12.3xq
cisco/ios 12.3xr
cisco/ios 12.3xs
cisco/ios 12.3xw
cisco/ios 12.3xx
cisco/ios 12.3xy
cisco/ios 12.3ya
cisco/ios 12.3yd
cisco/ios 12.3yg
... and 15 more
Published Feb 14, 2007
Tracked Since Feb 18, 2026