CVE-2008-3803
Cisco Security Advisory 20080924-vpn
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.
Un "error lógico" en Cisco IOS v12.0 a la v12.4, cuando está configurado un Multiprotocol Label Switching (MPLS) VPN "extendida a comunidades" (extended communities), en ocasiones provoca que sea usado un destino de ruta corrupta, lo que permite a atacantes remotos leer el tráfico de red desde otras VPN's en determinadas circunstancias.
Devices running Cisco IOS versions 12.0S, 12.2, 12.3 or 12.4 and configured for Multiprotocol Label Switching (MPLS) Virtual Private Networks (VPNs) or VPN Routing and Forwarding Lite (VRF Lite) and using Border Gateway Protocol (BGP) between Customer Edge (CE) and Provider Edge (PE) devices may permit information to propagate between VPNs. Workarounds are available to help mitigate this vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-27 CVE Reserved
- 2008-09-25 CVE Published
- 2024-08-07 CVE Updated
- 2025-06-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31990 | Third Party Advisory | |
http://www.securityfocus.com/bid/31366 | Third Party Advisory | |
http://www.securitytracker.com/id?1020940 | Broken Link | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5919 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014a9.shtml | 2022-06-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 12.0s Search vendor "Cisco" for product "Ios" and version "12.0s" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 12.0sx Search vendor "Cisco" for product "Ios" and version "12.0sx" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 12.0sz Search vendor "Cisco" for product "Ios" and version "12.0sz" | - |
Affected
|