
686868
© 2002, Cisco Systems, Inc. All rights reserved.
l2-security-bh.ppt
CDP Attacks
¥ Besides the information gathering benefit CDP offers an
attacker, there was a vulnerability in CDP that allowed
Cisco devices to run out of memory and potentially crash
if you sent it tons of bogus CDP packets
¥ If you need to run CDP, be sure to use IOS code with
minimum version numbers: 12.2(3.6)B, 12.2(4.1)S,
12.2(3.6)PB, 12.2(3.6)T, 12.1(10.1), 12.2(3.6) or CatOS code
6.3, 5.5, or 7.1 and later
¥ Problem was due to improper memory allocation for the
CDP process (basically there was no upper limit)
¥ Discovered by FX @ Phenolit
¥ For more information:
http://www.cisco.com/warp/public/707/cdp_issue.shtml
http://www.kb.cert.org/vuls/id/139491
Comentários a estes Manuais