Lucene search

K
cveCiscoCVE-2012-1344
HistoryAug 06, 2012 - 6:55 p.m.

CVE-2012-1344

2012-08-0618:55:00
CWE-119
cisco
web.nvd.nist.gov
30
cisco
ios
ssl vpn
denial of service
vulnerability
bug id
csctr86328

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

43.8%

Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.

Affected configurations

Nvd
Node
ciscoiosMatch15.1
OR
ciscoiosMatch15.2
VendorProductVersionCPE
ciscoios15.1cpe:2.3:o:cisco:ios:15.1:*:*:*:*:*:*:*
ciscoios15.2cpe:2.3:o:cisco:ios:15.2:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

43.8%

Related for CVE-2012-1344