Vulnerabilities > CVE-2012-3950 - Resource Management Errors vulnerability in Cisco IOS
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | CISCO |
NASL id | CISCO-SA-20120926-IOS-IPS.NASL |
description | Cisco IOS Software contains a vulnerability in the Intrusion Prevention System (IPS) feature that could allow an unauthenticated, remote attacker to cause a reload of an affected device if specific Cisco IOS IPS configurations exist. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available. |
last seen | 2019-10-28 |
modified | 2012-09-28 |
plugin id | 62374 |
published | 2012-09-28 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/62374 |
title | Cisco IOS Software Intrusion Prevention System Denial of Service Vulnerability (cisco-sa-20120926-ios-ips) |
References
- http://secunia.com/advisories/50777
- http://secunia.com/advisories/50777
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-ios-ips
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-ios-ips
- http://www.securityfocus.com/bid/55695
- http://www.securityfocus.com/bid/55695
- http://www.securitytracker.com/id?1027580
- http://www.securitytracker.com/id?1027580
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78882