Vulnerabilities > CVE-2005-4436 - Remote Denial Of Service vulnerability in Cisco EIGRP Protocol Unauthenticated Goodbye Packet

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE

Summary

Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS after 12.3(2), 12.3(3)B, and 12.3(2)T and other products, allows remote attackers to cause a denial of service by sending a "spoofed neighbor announcement" with (1) mismatched k values or (2) "goodbye message" Type-Length-Value (TLV).

Oval

accepted2008-09-08T04:00:24.411-04:00
classvulnerability
contributors
nameYuzheng Zhou
organizationHewlett-Packard
descriptionExtended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS after 12.3(2), 12.3(3)B, and 12.3(2)T and other products, allows remote attackers to cause a denial of service by sending a "spoofed neighbor announcement" with (1) mismatched k values or (2) "goodbye message" Type-Length-Value (TLV).
familyios
idoval:org.mitre.oval:def:5454
statusaccepted
submitted2008-05-26T11:06:36.000-04:00
titleCisco "EIGRP" Protocol "Goodbye Message" Packet Replay Vulnerability
version3