>> Cisco IOS Stack Group Bidding Protocol Denial of Service Vulnerability
Title : Cisco IOS Stack Group Bidding Protocol Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-0248 CVE ID : CVE-2006-0340
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-01-19
Technical Description
A vulnerability has been identified in Cisco IOS, which could be exploited by attackers to cause a denial of service. This flaw is due to an error in the Stack Group Bidding Protocol (SGBP) feature that does not properly handle specially crafted UDP packets sent to port 9900, which could be exploited by remote attackers to cause an affected device to become unresponsive and trigger a hardware reset, resulting in a denial of service condition.