First published: Wed Apr 23 2014(Updated: )
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.1\(1\)sy2 | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.1\(1\)sy | |
Cisco IOS | =15.1\(1\)sy1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4658 is classified as medium due to the potential for denial of service.
CVE-2012-4658 is a denial of service vulnerability affecting Cisco IOS.
To fix CVE-2012-4658, update to Cisco IOS version 15.1(1)SY3 or later.
CVE-2012-4658 affects Cisco IOS versions prior to 15.1(1)SY3.
Yes, CVE-2012-4658 can be exploited remotely by attackers to trigger a denial of service.