Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:5919 Date: 2008-09-24
Title: Cisco IOS MPLS VPN May Leak Information Vulnerability
Description: A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2008-3803
Family: ios
Platform(s): Cisco IOS Product(s):
Definition Synopsis: