CVE-2007-4430
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 13%
from disclosure to weapon0 days
Published on NVDAug 20
1st PoCAug 17
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30506⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=WAN%2C%20Routing%20and%20Switching&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddf7bc9http://secunia.com/advisories/26798https://puck.nether.net/pipermail/cisco-nsp/2007-August/043002.htmlhttps://puck.nether.net/pipermail/cisco-nsp/2007-August/043010.htmlhttp://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.htmlhttp://www.heise-security.co.uk/news/94526/http://www.securityfocus.com/bid/25352http://www.securitytracker.com/id?1018685http://www.vupen.com/english/advisories/2007/3136