Cisco IOS Software Multicast Source Discovery Protocol Vulnerability

This script is (C) 2012 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

The version of Cisco IOS installed on the remote host has a denial of
service vulnerability. Receiving an MSDP packet containing
encapsulated IGMP data can cause the device to reload. The host is
only affected when the interface configuration contains an explicitly
joined multicast group.

See also :

http://www.nessus.org/u?9fce961b

Solution :

Apply the relevant patch referenced in Cisco Security Advisory
cisco-sa-20120328-msdp.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 5.9
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 58568 ()

Bugtraq ID: 52759

CVE ID: CVE-2012-0382