First published: Wed Apr 23 2014(Updated: )
Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.1\(1\)sy3 | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.1\(1\)sy | |
Cisco IOS | =15.1\(1\)sy1 | |
Cisco IOS | =15.1\(1\)sy2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5014 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2012-5014, upgrade your Cisco IOS to version 15.1(2)SY or later.
CVE-2012-5014 is caused by remote authenticated users placing an SSH session client in a slow or idle state, leading to device crashes.
Affected Cisco IOS versions include any version prior to 15.1(2)SY.
CVE-2012-5014 can be exploited by any authenticated user, making it relatively easy to exploit.