CVE-2012-0385
published 2012-03-29CVE-2012-0385: The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.99%
85.9th percentile
The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Smart Install Denial of Service Vulnerability
vendor_cisco·2012-03-28·CVSS 7.8
CVE-2012-0385 [HIGH] Cisco IOS Software Smart Install Denial of Service Vulnerability
Cisco IOS Software Smart Install Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability in the Smart Install feature that could allow an unauthenticated, remote attacker to cause a reload of an affected device if the Smart Install feature is enabled. The vulnerability is triggered when an affected device processes a malformed Smart Install message on TCP port 4786.
Cisco has released software updates that address this vulnerability. A workaround may be available in some versions of Cisco IOS Software if the Smart Install feature is not needed.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-smartinstall
Note: The March 28, 2012, Cisco IOS Software Security Advisory bundl
Cisco
Cisco IOS Software Smart Install Denial of Service Vulnerability
vendor_cisco
CVE-2012-0385 Cisco IOS Software Smart Install Denial of Service Vulnerability
CVE-2012-0385: Cisco IOS Software Smart Install Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability in the Smart Install feature that could allow an unauthenticated, remote attacker to cause a reload of an affected device if the Smart Install feature is enabled. The vulnerability is triggered when an affected device processes a malformed Smart Install message on TCP port 4786. Cisco has released software updates that address this vulnerability. A workaround may be available in some versions of Cisco IOS Software if the Smart Install feature is not needed. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-smartinstall Note: The March 28, 2012, Cisco IOS Software Security A
GHSA
GHSA-5rv3-hx42-p8w4: The Smart Install feature in Cisco IOS 12
ghsa_unreviewed·2022-05-04
CVE-2012-0385 [HIGH] CWE-20 GHSA-5rv3-hx42-p8w4: The Smart Install feature in Cisco IOS 12
The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80694http://secunia.com/advisories/48610http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-smartinstallhttp://www.securityfocus.com/bid/52756http://www.securitytracker.com/id?1026867https://exchange.xforce.ibmcloud.com/vulnerabilities/74430http://osvdb.org/80694http://secunia.com/advisories/48610http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-smartinstallhttp://www.securityfocus.com/bid/52756http://www.securitytracker.com/id?1026867https://exchange.xforce.ibmcloud.com/vulnerabilities/74430
2012-03-29
Published