CVE-2007-0918
Last modified
CVE-2007-0918 is a vulnerability of currently unknown severity. The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.. EPSS estimates a 3.11% chance of exploitation in the next 30 days.
Description
The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.3t |
| Cisco | Ios | 12.3xq |
| Cisco | Ios | 12.3xr |
| Cisco | Ios | 12.3xs |
| Cisco | Ios | 12.3xw |
| Cisco | Ios | 12.3xx |
| Cisco | Ios | 12.3xy |
| Cisco | Ios | 12.3ya |
| Cisco | Ios | 12.3yd |
| Cisco | Ios | 12.3yg |
| Cisco | Ios | 12.3yh |
| Cisco | Ios | 12.3yi |
| Cisco | Ios | 12.3yj |
| Cisco | Ios | 12.3yk |
| Cisco | Ios | 12.3ym |
| Cisco | Ios | 12.3yq |
| Cisco | Ios | 12.3ys |
| Cisco | Ios | 12.3yt |
| Cisco | Ios | 12.3yx |
| Cisco | Ios | 12.3yz |
| Cisco | Ios | 12.4 |
| Cisco | Ios | 12.4mr |
| Cisco | Ios | 12.4t |
| Cisco | Ios | 12.4xa |
| Cisco | Ios | 12.4xb |
References
- http://osvdb.org/33053Broken Link
- http://secunia.com/advisories/24142Third Party Advisory
- http://www.securityfocus.com/bid/22549Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017631Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0597Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32474Third Party Advisory, VDB Entry
- http://osvdb.org/33053Broken Link
- http://secunia.com/advisories/24142Third Party Advisory
- http://www.securityfocus.com/bid/22549Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017631Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0597Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32474Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0918?
How severe is CVE-2007-0918?
How do I fix CVE-2007-0918?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0912Cross-Site Request Forgery (CSRF) vulnerability in admin/adm…
- CVE-2007-0913Unspecified vulnerability in Microsoft Powerpoint allows rem…
- CVE-2007-0914Race condition in the TCP subsystem for Solaris 10 allows re…
- CVE-2007-0915Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote…
- CVE-2007-0916Unspecified vulnerability in the Address and Routing Paramet…
- CVE-2007-0917The Intrusion Prevention System (IPS) feature for Cisco IOS …
- CVE-2007-0919Directory traversal vulnerability in Nickolas Grigoriadis Mi…
- CVE-2007-0920SQL injection vulnerability in philboard_forum.asp in Philbo…
- CVE-2007-0921Portal Search allows remote attackers to redirect a URL to a…
- CVE-2007-0922Cross-site scripting (XSS) vulnerability in buscador/buscado…
- CVE-2007-0923buscador/buscador.htm in Portal Search allows remote attacke…
- CVE-2007-0924Till Gerken phpPolls 1.0.3 allows remote attackers to bypass…
Are you affected by CVE-2007-0918?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
