CVE-2011-3289: Low severity cisco ios vulnerability
Published May 2, 2012
·Updated
Cisco IOS 12.4 and 15.0 through 15.2 allows physically proximate attackers to bypass the No Service Password-Recovery feature and read the start-up configuration via unspecified vectors, aka Bug ID CSCtr97640.
Affected Software
4 affected components
Cisco IOS=15.1
Cisco IOS=15.0
Cisco IOS=12.4
Cisco IOS=15.2
Event History
May 2, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3289?
CVE-2011-3289 has a High severity rating due to the ability of physically proximate attackers to bypass security features.
2
How do I fix CVE-2011-3289?
To fix CVE-2011-3289, it's recommended to upgrade to a version of Cisco IOS that does not contain this vulnerability.
3
Which versions of Cisco IOS are affected by CVE-2011-3289?
CVE-2011-3289 affects Cisco IOS versions 12.4, 15.0, 15.1, and 15.2.
4
What can attackers do by exploiting CVE-2011-3289?
By exploiting CVE-2011-3289, attackers can bypass the No Service Password-Recovery feature and access the start-up configuration.
5
Is physical access required to exploit CVE-2011-3289?
Yes, physical access to the device is required to exploit CVE-2011-3289.