CVE-2011-2586: Input Validation
Published May 2, 2012
·Updated
The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.
Affected Software
2 affected components
Cisco IOS=12.4
Cisco IOS=15.0
Event History
May 2, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2586?
CVE-2011-2586 is categorized as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2011-2586?
To mitigate CVE-2011-2586, upgrade to a non-vulnerable version of Cisco IOS, such as 15.1 or later.
3
What devices are affected by CVE-2011-2586?
CVE-2011-2586 affects Cisco IOS versions 12.4 and 15.0 specifically.
4
Can CVE-2011-2586 be exploited remotely?
Yes, CVE-2011-2586 can be exploited by user-assisted remote attackers.
5
What kind of issue does CVE-2011-2586 cause?
CVE-2011-2586 can lead to a denial of service by crashing the affected device.