First published: Sun Sep 16 2012(Updated: )
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3893 is classified as a denial of service vulnerability affecting the FlexVPN implementation in Cisco IOS.
To mitigate CVE-2012-3893, upgrade Cisco IOS to a version that does not have this vulnerability, specifically versions later than 15.3.
CVE-2012-3893 affects remote authenticated users who can exploit spoke-to-spoke traffic in Cisco IOS 15.2 and 15.3.
CVE-2012-3893 is caused by the FlexVPN implementation mishandling spoke-to-spoke traffic, leading to a potential crash.
Currently, the recommended approach for CVE-2012-3893 is to upgrade the affected Cisco IOS versions or implement network segmentation to limit spoke-to-spoke traffic.