IP-in-IP protocol routes arbitrary traffic by default
kb.cert.org
kb.cert.org
> This vulnerability causes an affected device to unexpectedly decapsulate and process IP in IP packets that are destined to a locally configured IP address, even when no tunnel configuration is present. Any input ACL configured on an inbound interface of the affected device is evaluated against the IP fields on the carrier IP packet prior to decapsulation; it would not be evaluated on the passenger IP packet.
> Under specific conditions, processing of a crafted IP in IP packet could cause the network stack process to crash on an affected device.
Ummmmm.... This sounds embarrasingly bad for Cisco. The crash DoS is just a cherry on top. But failing to filter tunneled packets is bit of a wtf, especially if you don't even have tunneling configured.
And despite this being marked as generic vuln, the gist really seem to be just squarely a Cisco implementation fault.
https://www.cisco.com/c/en/us/products/switches/data-center-...
That's a whole lot of high-end switches in high-sensitivity environment.
Cisco advisory: https://tools.cisco.com/security/center/content/CiscoSecurit...
Do they still have telnet open by default?
Edit: Now I see that some devices have been found that have IP-in-IP switched on by default which is crazily stupid.
If so, could they check those logs for IP-in-IP packets that might have been abusing this vulnerability?