CVE-2012-0339: Input Validation
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0339?
CVE-2012-0339 is classified as a high severity vulnerability due to the potential for unauthorized remote access.
How do I fix CVE-2012-0339?
To fix CVE-2012-0339, upgrade to a Cisco IOS version that is not vulnerable, such as versions later than 12.4 and 15.0.
What systems are affected by CVE-2012-0339?
CVE-2012-0339 affects Cisco IOS versions 12.2 through 12.4 and 15.0.
Can CVE-2012-0339 be exploited remotely?
Yes, CVE-2012-0339 can be exploited remotely by attackers using standard TELNET clients.
What attack vector is associated with CVE-2012-0339?
The attack vector for CVE-2012-0339 involves exploiting the improper enforcement of access-class commands in the IOS.