First published: Sun Sep 16 2012(Updated: )
sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Intrusion Prevention System | =6.0 | |
Cisco Intrusion Prevention System | =6.2 | |
Cisco Intrusion Prevention System | =7.0 | |
Cisco IPS Sensor Software | ||
Cisco IPS 4250 | ||
Cisco IPS Sensor Software | ||
Cisco IPS Sensor Software | ||
Cisco IPS 4270-20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3899 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2012-3899, upgrade the Cisco Intrusion Prevention System to a version that has addressed this vulnerability.
CVE-2012-3899 affects Cisco IPS version 6.0, 6.2, and 7.0 in addition to various 4200 series sensors.
CVE-2012-3899 allows remote attackers to exploit memory corruption, leading to process crashes and traffic-inspection outages.
There are no official workarounds documented for CVE-2012-3899; applying the recommended software update is essential.