CVE-2011-3271Cisco IOS vulnerability

5 documents5 sources
Severity
10.0CRITICALNVD
EPSS
25.0%
top 3.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3
Latest updateMay 17

Description

Unspecified vulnerability in the Smart Install functionality in Cisco IOS 12.2 and 15.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via crafted TCP packets to port 4786, aka Bug ID CSCto10165.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDcisco/ios12.2, 15.1+1

🔴Vulnerability Details

2
GHSA
GHSA-pcxh-cf4j-89xg: Unspecified vulnerability in the Smart Install functionality in Cisco IOS 122022-05-17
CVEList
CVE-2011-3271: Unspecified vulnerability in the Smart Install functionality in Cisco IOS 122011-10-03

💥Exploits & PoCs

1
Exploit-DB
IBM Websphere Application Server 7.0.0.13 - Cross-Site Request Forgery2011-06-15

📋Vendor Advisories

1
Cisco
Cisco IOS Software Smart Install Remote Code Execution Vulnerability2011-09-28
CVE-2011-3271 — Cisco IOS vulnerability | cvebase