>> Cisco IOS/CatOS VLAN Trunking Protocol DoS Vulnerability
Title : Cisco IOS/CatOS VLAN Trunking Protocol DoS Vulnerability VUPEN ID : VUPEN/ADV-2008-3031 CVE ID : CVE-2008-4963 CWE ID : CWE-399
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-06
Technical Description
A vulnerability has been identified in Cisco IOS and CatOS, which could be exploited by attackers to cause a denial of service. This issue is caused by an error when processing malformed VLAN Trunking Protocol (VTP) packets sent from the local network segment to a switch interface configured to operate as a trunk port while the device is operating in either server or client VTP mode, which could allow attackers to cause a vulnerable device to crash or reload, creating a denial of service condition.