CVE-2012-5014: Medium severity Cisco IOS vulnerability
Published Apr 23, 2014
·Updated
Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.
Affected Software
5 affected components
Cisco IOS<=15.1\(1\)sy3
Cisco IOS=15.1
Cisco IOS=15.1\(1\)sy
Cisco IOS=15.1\(1\)sy1
Cisco IOS=15.1\(1\)sy2
Event History
Apr 23, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:52 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5014?
CVE-2012-5014 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2012-5014?
To fix CVE-2012-5014, upgrade your Cisco IOS to version 15.1(2)SY or later.
3
What causes CVE-2012-5014?
CVE-2012-5014 is caused by remote authenticated users placing an SSH session client in a slow or idle state, leading to device crashes.
4
Which Cisco IOS versions are affected by CVE-2012-5014?
Affected Cisco IOS versions include any version prior to 15.1(2)SY.
5
Is CVE-2012-5014 easily exploitable?
CVE-2012-5014 can be exploited by any authenticated user, making it relatively easy to exploit.