CVE-2008-3798
published 2008-09-26CVE-2008-3798: Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of…
high7.8CVSS 3.1
AVNACLAuNCNINAC
Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_while_processing_ssl_packet | — | — |
Cisco
Vulnerability in Cisco IOS While Processing SSL Packet
vendor_cisco·2008-09-24·CVSS 7.8
CVE-2008-3798 [HIGH] CWE-399 Vulnerability in Cisco IOS While Processing SSL Packet
Vulnerability in Cisco IOS While Processing SSL Packet
A Cisco IOS device may crash while processing an SSL packet. This can
happen during the termination of an SSL-based session. The offending packet is
not malformed and is normally received as part of the packet exchange.
Cisco has released software updates that address this vulnerability. Aside from disabling affected services, there are no available
workarounds to mitigate an exploit of this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080924-ssl.
Note: The September 24, 2008 IOS Advisory bundled publication includes
twelve Security Advisories. Eleven of the advisories address vulnerabilities in
Cisco's IOS software, and one advisory addresses v
Cisco
Vulnerability in Cisco IOS While Processing SSL Packet
vendor_cisco
CVE-2008-3798 Vulnerability in Cisco IOS While Processing SSL Packet
CVE-2008-3798: Vulnerability in Cisco IOS While Processing SSL Packet
A Cisco IOS device may crash while processing an SSL packet. This can happen during the termination of an SSL-based session. The offending packet is not malformed and is normally received as part of the packet exchange. Cisco has released software updates that address this vulnerability. Aside from disabling affected services, there are no available
CWE: CWE-399, CWE-399
Bug IDs: CSCsj85065, CSCsj85065
GHSA
GHSA-rjpg-gjcq-25gr: Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2008-3798 [HIGH] GHSA-rjpg-gjcq-25gr: Cisco IOS 12
Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0146c.shtmlhttp://www.securitytracker.com/id?1020930http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6087http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0146c.shtmlhttp://www.securitytracker.com/id?1020930http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6087
2008-09-26
Published