Executive brief
A vulnerability in Cisco IOS NAT implementation allows remote attackers to cause a denial of service (device crash and reload) via crafted H.323 RAS packets. The issue stems from improper translation of H.323 messages using the Registration, Admission, and Status (RAS) protocol when NAT ALG is enabled.
Affected products
- Cisco IOS 12.4 through 15.6
Timeline
- 2017-09-27: disclosed: Initial Cisco advisory publication
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog