CVE-2012-1346: Medium severity Cisco Emergency Responder vulnerability
Published Aug 6, 2012
·Updated
Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369.
Affected Software
2 affected components
Cisco Emergency Responder=8.6
Cisco Emergency Responder=9.2
Event History
Aug 6, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1346?
CVE-2012-1346 is classified as a denial of service vulnerability that can lead to increased CPU consumption.
2
How do I fix CVE-2012-1346?
To mitigate CVE-2012-1346, apply available patches or updates provided by Cisco for affected versions of Emergency Responder.
3
Which versions of Cisco Emergency Responder are affected by CVE-2012-1346?
CVE-2012-1346 affects Cisco Emergency Responder versions 8.6 and 9.2.
4
What type of attack does CVE-2012-1346 involve?
CVE-2012-1346 involves remote attackers sending malformed UDP packets to cause a denial of service.
5
Is there a workaround for CVE-2012-1346?
Currently, disabling the CERPT port or restricting access to it are potential workarounds for CVE-2012-1346.