Vulnerabilities > Cisco > IOS > 12.3

DATE CVE VULNERABILITY TITLE RISK
2013-09-27 CVE-2013-5472 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
network
cisco CWE-20
7.1
2013-03-28 CVE-2013-1147 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does not properly validate TCP connection information, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a PT resource, aka Bug ID CSCtz35999.
network
low complexity
cisco CWE-119
7.8
2013-03-28 CVE-2013-1142 Race Condition vulnerability in Cisco IOS
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
network
low complexity
cisco CWE-362
7.8
2012-09-27 CVE-2012-4623 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
network
low complexity
cisco CWE-20
7.8
2012-09-27 CVE-2012-3950 Resource Management Errors vulnerability in Cisco IOS
The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.
network
cisco CWE-399
7.1
2012-09-27 CVE-2012-3949 Improper Input Validation vulnerability in Cisco Ios, IOS XE and Unified Communications Manager
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
network
low complexity
cisco CWE-20
7.8
2012-08-06 CVE-2012-1350 Unspecified vulnerability in Cisco products
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
network
low complexity
cisco
7.8
2012-05-03 CVE-2012-1327 Improper Access Control vulnerability in Cisco IOS
dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391.
low complexity
cisco CWE-284
6.1
2012-05-02 CVE-2012-0339 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.
network
low complexity
cisco CWE-20
5.0
2012-05-02 CVE-2012-0338 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113.
network
low complexity
cisco CWE-20
5.0