26360Third-party advisory
http://secunia.com/advisories/26360 CVE-2007-4286
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service
Record summary
CVE-2007-4286 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco IOS Next Hop Resolution Protocol (NHRP) - Denial of ServiceExploitDB exploitby Martin KlugeNot analyzed1 file
References
1020070808 Cisco IOS Next Hop Resolution Protocol VulnerabilityVendor advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a008089963b.shtml VU#201984Third-party advisory
http://www.kb.cert.org/vuls/id/201984 20070809 Cisco NHRP denial of service (cisco-sa-20070808-nhrp)mailing list
http://www.securityfocus.com/archive/1/475931/100/0/threaded 25238vdb entry
http://www.securityfocus.com/bid/25238 1018535vdb entry
http://www.securitytracker.com/id?1018535 ADV-2007-2818vdb entry
http://www.vupen.com/english/advisories/2007/2818 cisco-ios-nexthop-bo(35889)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35889 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4286 oval:org.mitre.oval:def:5675vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5675