First published: Thu Sep 23 2010(Updated: )
Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is enabled, allows remote attackers to cause a denial of service (memory consumption) by improperly disconnecting SSL sessions, leading to connections that remain in the CLOSE-WAIT state, aka Bug ID CSCtg21685.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.4mra | |
Cisco IOS | =12.4xj | |
Cisco IOS | =12.4xl | |
Cisco IOS | =12.4xm | |
Cisco IOS | =12.4mr | |
Cisco IOS | =12.4xt | |
Cisco IOS | =12.4gc | |
Cisco IOS | =15.1t | |
Cisco IOS | =12.4xf | |
Cisco IOS | =12.4xg | |
Cisco IOS | =12.4ya | |
Cisco IOS | =15.0m | |
Cisco IOS | =12.4xv | |
Cisco IOS | =12.4xw | |
Cisco IOS | =12.4xz | |
Cisco IOS | =12.4xd | |
Cisco IOS | =12.4xp | |
Cisco IOS | =12.4yd | |
Cisco IOS | =12.4mda | |
Cisco IOS | =12.4xk | |
Cisco IOS | =12.4 | |
Cisco IOS | =12.4sw | |
Cisco IOS | =12.4xa | |
Cisco IOS | =12.4xn | |
Cisco IOS | =12.4xe | |
Cisco IOS | =15.1\(1\)xb1 | |
Cisco IOS | =12.4yb | |
Cisco IOS | =12.4xb | |
Cisco IOS | =12.4xy | |
Cisco IOS | =12.4xc | |
Cisco IOS | =15.0xa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2836 is classified as a denial of service vulnerability with moderate severity.
To remediate CVE-2010-2836, update your Cisco IOS version to a non-affected release where the SSL VPN memory leak issue is resolved.
CVE-2010-2836 can lead to a denial of service by causing excessive memory consumption due to lingering SSL sessions.
CVE-2010-2836 affects specific versions of Cisco IOS including 12.4, 15.0, and 15.1.
Yes, CVE-2010-2836 can be exploited remotely by attackers disconnecting SSL sessions improperly.