CVE-2012-1344: Buffer Overflow
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1344?
CVE-2012-1344 has a high severity rating due to its potential to cause a denial of service by reloading the device.
How do I fix CVE-2012-1344?
To fix CVE-2012-1344, update Cisco IOS to version 15.3 or later where the vulnerability is patched.
Who is affected by CVE-2012-1344?
CVE-2012-1344 affects remote authenticated users who use a clientless SSL VPN on Cisco IOS versions 15.1 and 15.2.
What types of attacks does CVE-2012-1344 enable?
CVE-2012-1344 enables a denial of service attack due to device reloads triggered by refreshing the SSL VPN portal page.
When was CVE-2012-1344 disclosed?
CVE-2012-1344 was disclosed in 2012 as a vulnerability within specific versions of Cisco IOS.