CVE-2008-3803

A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.

Date published : 2008-09-26

http://www.securityfocus.com/bid/31366

http://www.cisco.com/en/US/products/products_security_advisory09186a0080a014a9.shtml