CVE-2008-3803

Cisco IOS 12.0-12.4 - VPN Traffic Exposure via MPLS Route Target Corruption

Title source: llm
STIX 2.1

Description

A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31990
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31366
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020940
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2670

Scores

EPSS 0.0265
EPSS Percentile 84.0%

Details

Status published
Products (3)
cisco/ios 12.0s
cisco/ios 12.0sx
cisco/ios 12.0sz
Published Sep 26, 2008
Tracked Since Feb 18, 2026