CVE-2012-0386: High severity cisco ios vulnerability
The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0386?
CVE-2012-0386 has a severity rating that indicates a denial of service vulnerability, potentially impacting system availability.
How do I fix CVE-2012-0386?
To fix CVE-2012-0386, upgrade the affected Cisco IOS or IOS XE software to a version that addresses this vulnerability.
Which Cisco IOS and IOS XE versions are affected by CVE-2012-0386?
CVE-2012-0386 affects Cisco IOS versions 12.2, 12.4, 15.0, 15.1, 15.2 and IOS XE versions 2.3.x through 2.6.x and 3.1.xS through 3.4.xS.
What type of attack does CVE-2012-0386 enable?
CVE-2012-0386 allows remote attackers to cause a denial of service resulting in device reload through a crafted username.
Is there a workaround for CVE-2012-0386?
While updating to a fixed version is recommended, temporarily limiting SSH access may act as a workaround for CVE-2012-0386.