CVE-2012-3924: Low severity cisco ios vulnerability
The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3924?
CVE-2012-3924 is classified as a denial of service vulnerability that can lead to a device crash.
How do I fix CVE-2012-3924?
To mitigate CVE-2012-3924, upgrade the affected Cisco IOS software to a version that addresses this vulnerability.
What versions are affected by CVE-2012-3924?
CVE-2012-3924 affects Cisco IOS versions 15.1 and 15.2 when DTLS is enabled.
What type of attack does CVE-2012-3924 involve?
CVE-2012-3924 involves a denial of service attack executed through a session involving a PPP over ATM (PPPoA) interface.
Who can exploit CVE-2012-3924?
Remote authenticated users can exploit CVE-2012-3924 to cause a denial of service on the affected device.