CVE-2006-4650
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect…
Does this matter?
Lower severity and a low EPSS score (3.17%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 3.17% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- cisco/ios
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21783
- http://securityreason.com/securityalert/1526
- http://securitytracker.com/id?1016799
- http://www.cisco.com/en/US/tech/tk827/tk369/tsd_technology_security_response09186a008072cd7b.html
- http://www.osvdb.org/28590
- http://www.phenoelit.de/stuff/CiscoGRE.txtVendor Advisory
- http://www.securityfocus.com/archive/1/445322/100/0/threaded
- http://www.securityfocus.com/bid/19878
- http://www.vupen.com/english/advisories/2006/3502
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28786
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5713
- http://secunia.com/advisories/21783
- http://securityreason.com/securityalert/1526
- http://securitytracker.com/id?1016799
- http://www.cisco.com/en/US/tech/tk827/tk369/tsd_technology_security_response09186a008072cd7b.html
- http://www.osvdb.org/28590
- http://www.phenoelit.de/stuff/CiscoGRE.txtVendor Advisory
- http://www.securityfocus.com/archive/1/445322/100/0/threaded
- http://www.securityfocus.com/bid/19878
- http://www.vupen.com/english/advisories/2006/3502
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28786
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5713
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.