Home / vulnerabilities cisco-sa-20070808-IOS-IPv6-leak.txt
Posted on 09 August 2007
Source : packetstormsecurity.org Link
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Cisco Security Advisory:
Cisco IOS Information Leakage Using IPv6 Routing Header
Advisory ID: cisco-sa-20070808-IOS-IPv6-leak
http://www.cisco.com/warp/public/707/cisco-sa-20070808-IOS-IPv6-leak.shtml
Revision 1.0
For Public Release 2007 August 08 1600 UTC (GMT)
- -----------------------------------------------------------------------
Summary
=======
Cisco IOS and Cisco IOS XR contain a vulnerability when processing
specially crafted IPv6 packets with a Type 0 Routing Header present.
Exploitation of this vulnerability can lead to information leakage on
affected IOS and IOS XR devices, and may also result in a crash of the
affected IOS device. Successful exploitation on an affected device
running Cisco IOS XR will not result in a crash of the device itself,
but may result in a crash of the IPv6 subsystem.
Cisco has made free software available to address this vulnerability
for affected customers. There are workarounds available to mitigate the
effects of the vulnerability.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20070808-IOS-IPv6-leak.shtml.
Note: The August 08, 2007 publication includes four Security Advisories
and one Security Response. The advisories all affect IOS, one
additionally affects Cisco Unified Communications Manager as well. Each
advisory lists the releases that correct the vulnerability described in
the advisory, and the advisories also detail the releases that correct
the vulnerabilities in all four advisories. Individual publication
links are listed below:
* Cisco IOS Information Leakage Using IPv6 Routing Header
http://www.cisco.com/warp/public/707/cisco-sa-20070808-IOS-IPv6-leak.shtml
* Cisco IOS Next Hop Resolution Protocol Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20070808-nhrp.shtml
* Cisco IOS Secure Copy Authorization Bypass Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20070808-scp.shtml
* Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
http://www.cisco.com/warp/public/707/cisco-sa-20070808-IOS-voice.shtml
* Cisco Unified MeetingPlace XSS Vulnerability
http://www.cisco.com/warp/public/707/cisco-sr-20070808-mp.shtml
Affected Products
=================
Vulnerable Products
+------------------
This vulnerability affects devices that are configured to use the IPv6
protocol and are running affected versions of one of the following
types of software:
* Cisco IOS
* Cisco IOS XR
To determine the software running on a Cisco IOS product, log in to the
device and issue the show version command to display the system banner.
Cisco IOS software will identify itself as "Internetwork Operating
System Software" or simply "IOS." On the next line of output, the image
name will be displayed between parentheses, followed by "Version" and
the Cisco IOS release name. Other Cisco devices will not have the show
version command, or will give different output.
The following example shows output from a device running an IOS image:
Router>show version
Cisco IOS Software, 7200 Software (C7200-IK9S-M), Version 12.3(14)T1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2005 by Cisco Systems, Inc.
Compiled Thu 31-Mar-05 08:04 by yiyan
Additional information about Cisco IOS release naming is available at
the following link:
http://www.cisco.com/en/US/products/sw/iosswrel/ps1828/products_white_paper09186a008018305e.shtml.
To determine whether IPv6 is configured on an IOS device, look for the
lines containing ipv6 in the Cisco IOS configuration, as shown in the
following example:
Router#show running-config | include ipv6
ipv6 address 2001:0DB8:C18:1::/64 eui-64
If the configuration contains a line or lines similar to the above
example, IPv6 is configured on the device. The exact IPv6 address will
vary in your configuration.
To determine whether IPv6 is configured on an IOS XR device, look for
the following lines in in the Cisco IOS XR configuration:
Router-IOS_XR#show ipv6 interface | include IPv6
IPv6 is enabled, link-local address is fe80::216:47ff:fee1:d987
IPv6 is disabled, link-local address unassigned
IPv6 is disabled, link-local address unassigned
If the output contains at least one line that reads IPv6 is enabled,
IPv6 is configured on the device.
Products Confirmed Not Vulnerable
+--------------------------------
No other Cisco products are currently known to be affected by this
vulnerability. In particular, the following devices are known not to be
affected:
* Cisco PIX and ASA Appliances
* Cisco Firewall Services Module (FWSM)
* Cisco MDS
Cisco PIX, ASA, and FWSM firewall products do not process packets
containing IPv6 Routing headers. All such packets will be silently
dropped.
Details
=======
Successful exploitation of the vulnerability described in this document
may result in swapping memory between the destination IPv6 address in
the IPv6 packet header and 16 bytes from the packet buffer memory.
Memory that can be accessed through this vulnerability can not be
further than 1500 bytes from the packet header start.
This vulnerability is documented for Cisco IOS as Cisco Bug ID
CSCef77013 and for Cisco IOS XR as Cisco Bug ID CSCsi74127.
Vulnerability Scoring Details
+----------------------------
Cisco is providing scores for the vulnerabilities in this advisory
based on the Common Vulnerability Scoring System (CVSS). The CVSS
scoring in this Security Advisory is done in accordance with CVSS
version 1.0.
Cisco will provide a base and temporal score. Customers can then
compute environmental scores to assist in determining the impact of the
vulnerability in individual networks.
Cisco PSIRT will set the bias in all cases to normal. Customers are
encouraged to apply the bias parameter when determining the
environmental impact of a particular vulnerability.
CVSS is a standards based scoring method that conveys vulnerability
severity and helps determine urgency and priority of response.
Cisco has provided an FAQ to answer additional questions regarding CVSS
at http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html.
Cisco has also provided a CVSS calculator to help compute the
environmental impact for individual networks at
http://intellishield.cisco.com/security/alertmanager/cvss.
CSCef77013 - Tighter parameter checking for IPv6
CVSS Base Score - 8
Access Vector - Remote
Access Complexity - Low
Authentication - Not Required
Confidentiality Impact - Partial
Integrity Impact - Partial
Availability Impact - Complete
Impact Bias - Normal
CVSS Temporal Score - 6.6
Exploitability - Functional
Remediation Level - Official-Fix
Report Confidence - Confirmed
CSCsi74127 - Processing of IPv6 headers
CVSS Base Score - 7
Access Vector - Remote
Access Complexity - Low
Authentication - Not Required
Confidentiality Impact - Partial
Integrity Impact - Partial
Availability Impact - Partial
Impact Bias - Normal
CVSS Temporal Score - 5.8
Exploitability - Functional
Remediation Level - Official-Fix
Report Confidence - Confirmed
Impact
======
Successful exploitation of this vulnerability may result in the
swapping of memory between the destination IPv6 address field and
packet buffer memory. This can lead to the leakage of data from the
buffer memory in the form of an IPv6 destination address and, in a
worst case scenario for devices running Cisco IOS, a complete crash of
the IOS device.
Note: Given that the destination IPv6 address will contain the contents
of a buffer memory, the packet may not get routed outside of the local
network. Depending on the exact destination address the packet may get
dropped by the next router or on the targeted router itself if it does
not have route to the newly formed IPv6 address.
In the case of Cisco IOS XR, successful exploitation will not crash the
whole device but only lead to a restart of the IPv6 subsystem.
Successful repeated exploitation of this vulnerability may lead to a
sustained denial of service (DoS) of all upper layer services that use
IPv6 as the transport protocol but not the whole device.
Software Versions and Fixes
===========================
When considering software upgrades, also consult
http://www.cisco.com/go/psirt and any subsequent advisories to
determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the
devices to be upgraded contain sufficient memory and that current
hardware and software configurations will continue to be supported
properly by the new release. If the information is not clear, contact
the Cisco Technical Assistance Center ("TAC") or your contracted
maintenance provider for assistance.
Each row of the Cisco IOS software table (below) names a Cisco IOS
release train. If a given release train is vulnerable, then the
earliest possible releases that contain the fix (along with the
anticipated date of availability for each, if applicable) are listed in
the "First Fixed Release" column of the table. The "Recommended
Release" column indicates the releases which have fixes for all the
published vulnerabilities at the time of this Advisory. A device
running a release in the given train that is earlier than the release
in a specific column (less than the First Fixed Release) is known to be
vulnerable. Cisco recommends upgrading to a release equal to or later
than the release in the "Recommended Releases" column of the table.
For further information about how Cisco IOS is built, numbered and
maintained, please see the following URL:
http://www.cisco.com/warp/public/620/1.html
+-------------------------------------------------------------+
| Major | Availability of Repaired Releases |
| Release | |
|--------------+----------------------------------------------|
| Affected | | Recommended |
| 12.0-Based | First Fixed Release | Release |
| Release | | |
|--------------+-----------------------------+----------------|
| 12.0 | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0DA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0DB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0DC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | 12.0(32)S8; available | 12.0(32)S8; |
| 12.0S | 21-Aug-07 | available |
| | | 21-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.0SC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0SL | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0SP | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.0(32)S8; |
| 12.0ST | 12.0(32)S8 available | available |
| | 21-Aug-07 | 21-Aug-07 |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.0(32)S8; |
| 12.0SX | 12.0(32)S8 available | available |
| | 21-Aug-07 | 21-Aug-07 |
|--------------+-----------------------------+----------------|
| | 12.0(32)SY4; available | 12.0(32)SY4; |
| 12.0SY | 21-Aug-07 | available |
| | | 21-Aug-07 |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | |
| 12.0SZ | 12.0(32)S8 available | |
| | 21-Aug-07 | |
|--------------+-----------------------------+----------------|
| 12.0T | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0W | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0WC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0WT | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XD | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XF | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XG | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XH | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XI | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XJ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XK | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XL | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XM | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XN | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XQ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XR | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XS | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XV | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.0XW | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| Affected | | Recommended |
| 12.1-Based | First Fixed Release | Release |
| Release | | |
|--------------+-----------------------------+----------------|
| 12.1 | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1AA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1AX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1AY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1AZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1CX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1DA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1DB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1DC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1E | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EO | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EU | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EV | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EW | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1EZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1GA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1GB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1T | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XD | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XF | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XG | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XH | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XI | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XJ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XK | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XL | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XM | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XN | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XO | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XP | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XQ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XR | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XS | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XT | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.1XU | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.1XV | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.1XW | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1XZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.1YB | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.1YC | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.1YD | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.1YE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YF | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YG | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YH | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YI | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.1YJ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| Affected | | Recommended |
| 12.2-Based | First Fixed Release | Release |
| Release | | |
|--------------+-----------------------------+----------------|
| 12.2 | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2B | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.3(17b)BC8 |
| 12.2BC | 12.3(17a)BC | |
| | | 12.3(21a)BC3 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2BW | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2BY | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| 12.2BZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.3(17b)BC8 |
| 12.2CX | 12.3(17a)BC | |
| | | 12.3(21a)BC3 |
|--------------+-----------------------------+----------------|
| 12.2CY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2CZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2DA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2DD | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2DX | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| | | All Cat4K |
| | | platforms: |
| | | |
| | | 12.2(25)EWA10 |
| | | |
| 12.2EU | Vulnerable; first fixed in | 12.2(31)SGA3 |
| | 12.2(25)EWA10 | |
| | | 12.2(37)SG1 |
| | | |
| | | 12.2(40)SG; |
| | | available |
| | | Oct-07 |
|--------------+-----------------------------+----------------|
| | | All Cat4K |
| | | platforms: |
| | | |
| | | 12.2(25)EWA10 |
| | | |
| 12.2EW | Vulnerable; first fixed in | 12.2(31)SGA3 |
| | 12.2(25)EWA10 | |
| | | 12.2(37)SG1 |
| | | |
| | | 12.2(40)SG; |
| | | available |
| | | Oct-07 |
|--------------+-----------------------------+----------------|
| | | All Cat4K |
| | | platforms: |
| | | |
| | | 12.2(25)EWA10 |
| | | |
| 12.2EWA | 12.2(25)EWA10 | 12.2(31)SGA3 |
| | | |
| | | 12.2(37)SG1 |
| | | |
| | | 12.2(40)SG; |
| | | available |
| | | Oct-07 |
|--------------+-----------------------------+----------------|
| 12.2EX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2EY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)SEE4; |
| 12.2EZ | 12.2(25)SEE4 | available |
| | | 07-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.2FX | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2FY | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.2(40)SE; |
| | | available |
| | Vulnerable; first fixed in | 24-Aug-07 |
| 12.2FZ | 12.2(35)SE | |
| | | 12.2(37)SE1 |
| | | |
| | | 12.2(35)SE5 |
|--------------+-----------------------------+----------------|
| 12.2IXA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2IXB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2IXC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2IXD | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2JA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2JK | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2MB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | 12.2(15)MC2h | |
| 12.2MC | | 12.2(15)MC2j |
| | 12.2(15)MC2j | |
|--------------+-----------------------------+----------------|
| | 12.2(14)S18 | |
| | | |
| | 12.2(18)S13 | |
| | | 12.2(25)S13 |
| 12.2S | 12.2(20)S14 | |
| | | 12.2(14)S19 |
| | 12.2(25)S13 | |
| | | |
| | 12.2(30)S | |
|--------------+-----------------------------+----------------|
| 12.2SB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SBC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)SEE4; |
| 12.2SEA | 12.2(25)SEE4 | available |
| | | 07-Aug-07 |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)SEE4; |
| 12.2SEB | 12.2(25)SEE4 | available |
| | | 07-Aug-07 |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)SEE4; |
| 12.2SEC | 12.2(25)SEE4 | available |
| | | 07-Aug-07 |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)SEE4; |
| 12.2SED | 12.2(25)SEE4 | available |
| | | 07-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.2SEE | 12.2(25)SEE4 | 12.2(25)SEE4 |
|--------------+-----------------------------+----------------|
| 12.2SEF | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SEG | 12.2(25)SEG3 | 12.2(25)SEG3 |
|--------------+-----------------------------+----------------|
| | 12.2(25)SG2; available | All Cat4K |
| | 13-Aug-07 | platforms: |
| | | |
| | 12.2(31)SG1 | 12.2(25)SG2 |
| | | |
| 12.2SG | 12.2(31)SG | 12.2(37)SG1 |
| | | |
| | 12.2(37)SG | 12.2(31)SG2 |
| | | |
| | 12.2(40)SG; available | 12.2(40)SG; |
| | 24-Oct-07 | available |
| | | Oct-07 |
|--------------+-----------------------------+----------------|
| 12.2SGA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SL | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SM | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SO | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SRA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SRB | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2SU | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| | 12.2(27)SV2 | |
| | | |
| | 12.2(27)SV3 | |
| | | |
| | 12.2(27)SV1 | |
| | | 12.2(29)SV4; |
| 12.2SV | 12.2(28)SV1 | available |
| | | 14-Oct-07 |
| | 12.2(29)SV | |
| | | |
| | 12.2(29a)SV | |
| | | |
| | 12.2(29b)SV | |
|--------------+-----------------------------+----------------|
| 12.2SVA | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SVC | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SW | 12.2(25)SW11 | 12.2(25)SW11 |
|--------------+-----------------------------+----------------|
| 12.2SX | Vulnerable; first fixed in | |
| | 12.2(18)SXE | |
|--------------+-----------------------------+----------------|
| 12.2SXA | Vulnerable; first fixed in | |
| | 12.2(18)SXE | |
|--------------+-----------------------------+----------------|
| 12.2SXB | Vulnerable; first fixed in | 12.2(18)SXF10 |
| | 12.2(18)SXE | |
|--------------+-----------------------------+----------------|
| 12.2SXD | Vulnerable; contact TAC | |
|--------------+-----------------------------+----------------|
| 12.2SXE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SXF | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SXH | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2SY | Vulnerable; first fixed in | |
| | 12.2(18)SXE | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.2(25)S13 |
| 12.2SZ | 12.2(30)S | |
| | | 12.2(14)S19 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2T | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.2TPC | 12.2(8)TPC10c; available | 12.2(8)TPC10c |
| | 17-Aug-07 | |
|--------------+-----------------------------+----------------|
| 12.2UZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| 12.2VZ | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XA | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XB | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.4(12c) |
| | | |
| | | 12.4(3h) |
| | | |
| | | 12.4(5c) |
| | | |
| | | 12.4(8d); |
| | Vulnerable; first fixed in | available |
| 12.2XC | 12.3(14)T | 03-Sep-07 |
| | | |
| | | 12.4(7f) |
| | | |
| | | 12.4(16) |
| | | |
| | | 12.4(10c) |
| | | |
| | | 12.4(13d) |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XD | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.2XE | Not Vulnerable | |
|--------------+-----------------------------+----------------|
| | Vulnerable; first fixed in | 12.3(17b)BC8 |
| 12.2XF | 12.3(17a)BC | |
| | | 12.3(21a)BC3 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XG | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XH | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XI | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XJ | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XK | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XL | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XM | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XN | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| | | 12.3(23) |
| | | |
| | | 12.3(20a) |
| | | |
| | | 12.3(21b) |
| | | |
| | | 12.3(22a) |
| | Vulnerable; first fixed in | |
| 12.2XQ | 12.3(15) | 12.3(18a) |
| | | |
| | | 12.3(19a); |
| | | available |
| | | 16-Aug-07 |
| | | |
| | | 12.3(17c); |
| | | available |
| | | 16-Aug-07 |
|--------------+-----------------------------+----------------|
| 12.2XR | Not Vulnerable | |
|-----------