CVE-2012-0384Improper Privilege Management in Cisco IOS

Severity
7.2HIGHNVD
EPSS
0.4%
top 36.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29
Latest updateMay 4

Description

Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDcisco/ios778 versions+777
NVDcisco/ios_xe36 versions+35

🔴Vulnerability Details

2
GHSA
GHSA-vp46-7xjp-2x37: Cisco IOS 122022-05-04
CVEList
CVE-2012-0384: Cisco IOS 122012-03-29

📋Vendor Advisories

1
Cisco
Cisco IOS Software Command Authorization Bypass2012-03-28

📄Research Papers

1
arXiv
Identifying Relevant Information Cues for Vulnerability Assessment Using CVSS2018-03-20
CVE-2012-0384 — Improper Privilege Management in Cisco | cvebase