Lucene search

K
cve[email protected]CVE-2012-4661
HistoryOct 29, 2012 - 8:55 p.m.

CVE-2012-4661

2012-10-2920:55:01
CWE-119
web.nvd.nist.gov
27
cve-2012-4661
cisco
asa
asasm
catalyst 6500
dcerpc
buffer overflow
remote code execution
vulnerability

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:P/A:C

8.1 High

AI Score

Confidence

Low

0.083 Low

EPSS

Percentile

94.4%

Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 before 4.1(9) in Cisco Catalyst 6500 series switches and 7600 series routers might allow remote attackers to execute arbitrary code via a crafted DCERPC packet, aka Bug IDs CSCtr21359 and CSCtr27522.

Affected configurations

NVD
Node
ciscoadaptive_security_appliance_softwareMatch8.3\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.3\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(1.11\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(2.11\)
OR
ciscoadaptive_security_appliance_softwareMatch8.5
OR
ciscoadaptive_security_appliance_softwareMatch8.5\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.5\(1.4\)
OR
ciscoadaptive_security_appliance_softwareMatch8.6
OR
ciscoadaptive_security_appliance_softwareMatch8.6\(1\)
AND
cisco5500_series_adaptive_security_appliance
OR
cisco7600_router
OR
ciscocatalyst_6500
OR
ciscocatalyst_6503-eMatch-
OR
ciscocatalyst_6504-eMatch-
OR
ciscocatalyst_6506-eMatch-
OR
ciscocatalyst_6509-eMatch-
OR
ciscocatalyst_6509-neb-aMatch-
OR
ciscocatalyst_6509-v-eMatch-
OR
ciscocatalyst_6513Match-
OR
ciscocatalyst_6513-eMatch-

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:P/A:C

8.1 High

AI Score

Confidence

Low

0.083 Low

EPSS

Percentile

94.4%