First published: Thu Mar 27 2014(Updated: )
The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 | |
Cisco IOS | =15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2112 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2014-2112, it's recommended to upgrade your Cisco IOS to a version that addresses this vulnerability.
CVE-2014-2112 affects Cisco IOS versions 15.1 through 15.4.
CVE-2014-2112 involves denial of service attacks through crafted HTTP requests.
There are no specified workarounds for CVE-2014-2112, the best defense is to apply the necessary updates.