CVE-2012-0384: High severity cisco ios vulnerability
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0384?
CVE-2012-0384 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive systems.
How do I fix CVE-2012-0384?
To fix CVE-2012-0384, update your Cisco IOS or IOS XE software to a version that has been patched for this vulnerability.
What versions of Cisco IOS are affected by CVE-2012-0384?
CVE-2012-0384 affects Cisco IOS versions 12.2 through 12.4, and 15.0 through 15.2, along with certain versions of IOS XE.
Can unprivileged users exploit CVE-2012-0384?
Yes, CVE-2012-0384 can be exploited by remote authenticated users with lower privileges to bypass access controls in the affected Cisco IOS.
Is there a workaround for CVE-2012-0384?
One possible workaround for CVE-2012-0384 is to disable AAA authorization, although this may reduce overall system security.