First published: Wed Apr 23 2014(Updated: )
The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local users to cause a denial of service (device reload) via a "no object-group" command followed by an object-group command, aka Bug ID CSCts16133.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.1 | |
Cisco Catalyst 6500-E | ||
Cisco Catalyst 7600 Series | ||
All of | ||
Cisco IOS | <=15.1 | |
Any of | ||
Cisco Catalyst 6500-E | ||
Cisco Catalyst 7600 Series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5037 has a high severity rating, leading to potential denial of service on affected Cisco devices.
To fix CVE-2012-5037, upgrade Cisco IOS to version 15.1(1)SY or later on affected devices.
CVE-2012-5037 affects Cisco Catalyst 6500 and 7600 devices running IOS versions prior to 15.1(1)SY.
CVE-2012-5037 requires local access to execute the exploit, making it less likely to be exploited remotely.
CVE-2012-5037 is triggered by executing a "no object-group" command followed by an object-group command.