Cisco IOS Software IP Service Level Agreement Vulnerability
14 Mar. 2012
Summary
Successful exploitation of the vulnerability described in this document may result in the reload of a vulnerable device. Repeated exploitation could result in a DoS condition.
.Vulnerable Systems:
*Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.0(1)M1
The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3.3.x, allows remote attackers to cause a denial of service (memory corruption and device reload) via malformed IP SLA packets, aka Bug ID CSCtk67073.
Vendor Status:
Cisco has issued an update to correct this vulnerability
Disclosure Timeline:
2011-Oct-10 Clarify malformed IP SLA packets in Details section.
2011-Oct-07 Updated show running-config command nomenclature in Details section
2011-Sep-28 Initial public releas