CVE-2011-1624
published 2011-08-18CVE-2011-1624: Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.21%
65.3th percentile
Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2 sessions, aka Bug ID CSCto62631.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software SSH Banner Processing Error Denial of Service Vulnerability
vendor_cisco·2011-08-24·CVSS 7.8
CVE-2011-1624 [HIGH] CWE-399 Cisco IOS Software SSH Banner Processing Error Denial of Service Vulnerability
Cisco IOS Software SSH Banner Processing Error Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of login banners by Cisco IOS Software. An authenticated, remote attacker could exploit this vulnerability by logging in via SSH using two sessions. If successful, the attacker could cause the device to reload, resulting in a DoS condition.
Cisco confirmed the vulnerability in software release notes and released updated software.
To exploit the vulnerability, an attacker must be able to log in via SSH to a targeted device. The access requirement restricts the source of exploits to current users of an affected system. Exploits
GHSA
GHSA-gq4m-pjfx-4r44: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2011-1624 [HIGH] GHSA-gq4m-pjfx-4r44: Cisco IOS 12
Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2 sessions, aka Bug ID CSCto62631.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/docs/switches/lan/cisco_ie3000/software/release/12.2_58_se/release/notes/OL24335.htmlhttps://supportforums.cisco.com/message/3356210http://www.cisco.com/en/US/docs/switches/lan/cisco_ie3000/software/release/12.2_58_se/release/notes/OL24335.htmlhttps://supportforums.cisco.com/message/3356210
2011-08-18
Published