Lucene search

K
ciscoCiscoCISCO-SA-20120823-CVE-2012-1338
HistoryAug 23, 2012 - 6:12 p.m.

Cisco IOS Authentication Request Processing Denial of Service Vulnerability

2012-08-2318:12:45
tools.cisco.com
8

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

43.8%

Cisco IOS contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability is due to improper handling of web authentication requests. An authenticated, remote attacker could exploit the vulnerability by sending malicious authentication requests to the affected software. Successful exploitation could cause a DoS condition.

Cisco has confirmed the vulnerability and released software updates.

To exploit the vulnerability, authentication is required, and an attacker may require access to networks adjacent to a targeted device. These requirements increase the difficulty of exploitation.

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

43.8%

Related for CISCO-SA-20120823-CVE-2012-1338