Vulnerability Development mailing list archives

Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled.


From: "J.S. Morrison" <highlander () chatcrap com>
Date: Wed, 16 May 2001 11:28:37 +0200

Hi

It's possible to crash Cisco Catalyst 2900XL with a empty UDP
packet to port 161 when SNMP is disabled. (Other switches also?)

The crash only occurs when the switch is booted with SNMP disabled.
Seems that SNMP is listening, even if SNMP is disabled.. (?)

I have only tested this with Software Version 12.0(5.2)XU,
on my WS-C2924C-XL-EN switch.

Workaround: Enable SNMP, or enable SNMP and then disable SNMP.

Vendor notified 19 April 2001.
No response yet.

A simple empty UDP packet sender included.

--
\0x62\0x61\0x73\0x68\0x69\0x73

Attachment: c2900xl-crash.tgz
Description: gzip compressed data, deflated, last modified: Thu May 3 00:03:58 2001, os: Unix


Current thread: