The cat6000-dot1x component in Cisco IOS 12.2 prior to 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authentication dot1x enabled port and (2) a loop between a dot1x enabled port and a non-dot1x port, which allows remote malicious users to cause a denial of service (traffic storm) via unspecified vectors that trigger many Spanning Tree Protocol (STP) Bridge Protocol Data Unit (BPDU) frames, aka Bug ID CSCtq36327.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco ios |