First published: Wed May 02 2012(Updated: )
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.2 | |
Cisco IOS | =12.3 | |
Cisco IOS | =12.4 | |
Cisco IOS | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0339 is classified as a high severity vulnerability due to the potential for unauthorized remote access.
To fix CVE-2012-0339, upgrade to a Cisco IOS version that is not vulnerable, such as versions later than 12.4 and 15.0.
CVE-2012-0339 affects Cisco IOS versions 12.2 through 12.4 and 15.0.
Yes, CVE-2012-0339 can be exploited remotely by attackers using standard TELNET clients.
The attack vector for CVE-2012-0339 involves exploiting the improper enforcement of access-class commands in the IOS.