CVE-2007-4430 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 13.3% (pctl 96)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 13.28% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-20 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| cisco | cbos |
| cisco | cli |
| cisco | ids |
| cisco | ios |
| cisco | ios xr |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco IOS 12.3 - Show IP BGP Regexp Remote Denial of Service | 2007-08-17 |
References
- http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=WAN%2C%20Routing%20and%20Switching&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddf7bc9
- http://secunia.com/advisories/26798
- http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html
- http://www.heise-security.co.uk/news/94526/
- http://www.securityfocus.com/bid/25352
- http://www.securitytracker.com/id?1018685
- http://www.vupen.com/english/advisories/2007/3136
- https://puck.nether.net/pipermail/cisco-nsp/2007-August/043002.html
- https://puck.nether.net/pipermail/cisco-nsp/2007-August/043010.html
- http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=WAN%2C%20Routing%20and%20Switching&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddf7bc9
- http://secunia.com/advisories/26798
- http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html
- http://www.heise-security.co.uk/news/94526/
- http://www.securityfocus.com/bid/25352
- http://www.securitytracker.com/id?1018685
- http://www.vupen.com/english/advisories/2007/3136
- https://puck.nether.net/pipermail/cisco-nsp/2007-August/043002.html
- https://puck.nether.net/pipermail/cisco-nsp/2007-August/043010.html
→ the Explorer · watch your stack · NVD