| PROBLEM: | Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulenrability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operaiton. |
| PLATFORM: | Cisco Intrusion Prevention System version 5.x prior to 5.1(8)E2 Cisco Intrusion Prevention System version 6.x prior to 6.0(5)E2 Cisco IPS platforms ship with gigabit network interfaces and are vulnerable if they are deployed in inline mode: 4235 4240 4250 4250SX * 4250TX 4250XL *4255 4260 4270 |
| DAMAGE: | Denial of Service. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Successful exploitation of the vulnerability may result in a network denial of service condition. A power cycle is required to recover operations. An attacker may be able to evade access controls and detection of malicious activity int he case of Cisco IPS 4260-4270 platforms that have hardware bypass configured to pass traffic in the event of a kernel panic. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.8 6.4 (AV:N/AC:M/Au:N/C:P/I:N/A:C/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-319.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a00809b3842.shtml |
| CVE: | CVE-2008-2060 |
[***** Start Cisco Security Advisory Document ID: 107191 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable.
Cisco has released free software updates that address this vulnerability. There is a workaround for this vulnerability.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080618-ips.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 107191 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org