CVE-2012-0381
published 2012-03-29CVE-2012-0381: The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.85%
89.0th percentile
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
Affected
759 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Internet Key Exchange Vulnerability
vendor_cisco·2012-03-28·CVSS 7.8
CVE-2012-0381 [HIGH] Cisco IOS Internet Key Exchange Vulnerability
Cisco IOS Internet Key Exchange Vulnerability
The Cisco IOS Software Internet Key Exchange (IKE) feature
contains a denial of service (DoS) vulnerability.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike
Note: The March 28, 2012, Cisco IOS Software Security Advisory bundled publication includes nine Cisco Security Advisories. Each advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well as the Cisco IOS Software releases that correct all vulnerabilities in the March 2012 bundled publication.
Individual publication links are in "Cisco Event Response
Cisco
Cisco IOS Internet Key Exchange Vulnerability
vendor_cisco
CVE-2012-0381 Cisco IOS Internet Key Exchange Vulnerability
CVE-2012-0381: Cisco IOS Internet Key Exchange Vulnerability
The Cisco IOS Software Internet Key Exchange (IKE) feature contains a denial of service (DoS) vulnerability. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike Note: The March 28, 2012, Cisco IOS Software Security Advisory bundled publication includes nine Cisco Security Advisories. Each advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well as the Cisco IOS Software releases that correct all vulnerabilities in the March 2012 bundled publication. Individual publication links are in "Cisco Ev
GHSA
GHSA-34wg-h45c-wrjc: The IKEv1 implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-04
CVE-2012-0381 [HIGH] GHSA-34wg-h45c-wrjc: The IKEv1 implementation in Cisco IOS 12
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80700http://secunia.com/advisories/48605http://secunia.com/advisories/48607http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ikehttp://www.securityfocus.com/bid/52757http://www.securitytracker.com/id?1026863https://exchange.xforce.ibmcloud.com/vulnerabilities/74427http://osvdb.org/80700http://secunia.com/advisories/48605http://secunia.com/advisories/48607http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ikehttp://www.securityfocus.com/bid/52757http://www.securitytracker.com/id?1026863https://exchange.xforce.ibmcloud.com/vulnerabilities/74427
2012-03-29
Published