CVE-2012-3923: Low severity cisco ios vulnerability
The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3923?
CVE-2012-3923 is classified as a denial of service vulnerability that can result in device crashes.
How do I fix CVE-2012-3923?
To address CVE-2012-3923, enable DTLS on the affected Cisco IOS versions or apply recommended patches from Cisco.
Which Cisco IOS versions are affected by CVE-2012-3923?
CVE-2012-3923 affects Cisco IOS versions 12.4, 15.0, 15.1, and 15.2.
What types of devices are impacted by CVE-2012-3923?
Devices using the SSLVPN implementation in the specified Cisco IOS versions are impacted by CVE-2012-3923.
Can remote authenticated users exploit CVE-2012-3923?
Yes, remote authenticated users can exploit CVE-2012-3923 through sessions involving PPP over ATM interfaces.