Datasheet
132
Release Notes for Cisco IOS Release 12.1E on the Catalyst 6500 and Cisco 7600 Supervisor Engine and MSFC
OL-2310-11
Caveats
Release 12.1(26)E and Rebuilds
• General Caveats, page 132
• FlexWAN Caveats, page 152
• Service Module Caveats, page 155
• OSM Caveats, page 157
Note The caveat lists for Release 12.1(26)E and rebuilds are updated frequently.
General Caveats
• Open General Caveats in Release 12.1(26)E9, page 132
• Resolved General Caveats in Release 12.1(26)E9, page 132
• Resolved General Caveats in Release 12.1(26)E8, page 134
• Resolved General Caveats in Release 12.1(26)E7, page 136
• Resolved General Caveats in Release 12.1(26)E6, page 139
• Resolved General Caveats in Release 12.1(26)E5, page 139
• Resolved General Caveats in Release 12.1(26)E4, page 141
• Resolved General Caveats in Release 12.1(26)E3, page 143
• Resolved General Caveats in Release 12.1(26)E2, page 143
• Resolved General Caveats in Release 12.1(26)E1, page 144
• Resolved General Caveats in Release 12.1(26)E, page 145
Open General Caveats in Release 12.1(26)E9
None.
Resolved General Caveats in Release 12.1(26)E9
• CSCin95836—Resolved in Release 12.1(26)E9.
The Cisco Next Hop Resolution Protocol (NHRP) feature in Cisco IOS contains a vulnerability that
can result in a restart of the device or possible remote code execution.
NHRP is a primary component of the Dynamic Multipoint Virtual Private Network (DMVPN)
feature.
NHRP can operate in three ways: at the link layer (Layer 2), over Generic Routing Encapsulation
(GRE) and multipoint GRE (mGRE) tunnels and directly on IP (IP protocol number 54). This
vulnerability affects all three methods of operation.
NHRP is not enabled by default for Cisco IOS.
This vulnerability is addressed by Cisco bug IDs CSCin95836 for non-12.2 mainline releases and
CSCsi23231 for 12.2 mainline releases.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20070808-nhrp.shtml.