CVE-2019-12656: Cisco IOx Application Environment Denial of Service Vulnerability
A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12656?
CVE-2019-12656 is a vulnerability in the IOx application environment of multiple Cisco platforms that could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition.
Which Cisco platforms are affected by CVE-2019-12656?
CVE-2019-12656 affects Cisco IOS versions 1.6.0.0 and 1.8.0, as well as Cisco Industrial Ethernet 2000 Series Firmware version 15.2(6)e.
What is the severity level of CVE-2019-12656?
CVE-2019-12656 has a severity level of 7.5, which is considered high.
How can I fix CVE-2019-12656?
To fix CVE-2019-12656, Cisco recommends applying the necessary updates or workarounds as mentioned in the advisory provided by Cisco.
Where can I find more information about CVE-2019-12656?
You can find more information about CVE-2019-12656 in the Cisco Security Advisory at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-iox