CVE-2012-3893: Medium severity Cisco IOS vulnerability
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3893?
CVE-2012-3893 is classified as a denial of service vulnerability affecting the FlexVPN implementation in Cisco IOS.
How do I fix CVE-2012-3893?
To mitigate CVE-2012-3893, upgrade Cisco IOS to a version that does not have this vulnerability, specifically versions later than 15.3.
Who is affected by CVE-2012-3893?
CVE-2012-3893 affects remote authenticated users who can exploit spoke-to-spoke traffic in Cisco IOS 15.2 and 15.3.
What causes the vulnerability CVE-2012-3893?
CVE-2012-3893 is caused by the FlexVPN implementation mishandling spoke-to-spoke traffic, leading to a potential crash.
Is there a workaround for CVE-2012-3893?
Currently, the recommended approach for CVE-2012-3893 is to upgrade the affected Cisco IOS versions or implement network segmentation to limit spoke-to-spoke traffic.