CVE-2012-0385: Input Validation
Published Mar 29, 2012
·Updated
The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.
Affected Software
4 affected components
Cisco IOS=12.2
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Event History
Mar 29, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0385?
CVE-2012-0385 has been classified with a severity level that indicates it can cause a denial of service.
2
How do I fix CVE-2012-0385?
To fix CVE-2012-0385, it is recommended to disable the Smart Install feature on affected Cisco IOS devices.
3
Which versions of Cisco IOS are affected by CVE-2012-0385?
CVE-2012-0385 affects Cisco IOS versions 12.2 and 15.0 through 15.2.
4
What type of attack does CVE-2012-0385 enable?
CVE-2012-0385 enables remote attackers to send malformed messages that can cause device reloads, leading to denial of service.
5
Is there a workaround for CVE-2012-0385 if I cannot immediately update my Cisco IOS?
A temporary workaround for CVE-2012-0385 is to block TCP port 4786, which is used by the Smart Install feature.