CVE-2012-1311
published 2012-03-29CVE-2012-1311: The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to…
PriorityP334high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.01%
78.8th percentile
The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software RSVP Denial of Service Vulnerability
vendor_cisco·2012-03-28·CVSS 7.8
CVE-2012-1311 [HIGH] Cisco IOS Software RSVP Denial of Service Vulnerability
Cisco IOS Software RSVP Denial of Service Vulnerability
Cisco IOS Software and Cisco IOS XE Software contain a vulnerability in the RSVP feature when used on a device configured with VPN routing and forwarding (VRF) instances. This vulnerability could allow an unauthenticated, remote attacker to cause an interface wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. This vulnerability could be exploited repeatedly to cause an extended DoS condition.
A workaround is available to mitigate this vulnerability.
Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2
Cisco
Cisco IOS Software RSVP Denial of Service Vulnerability
vendor_cisco
CVE-2012-1311 Cisco IOS Software RSVP Denial of Service Vulnerability
CVE-2012-1311: Cisco IOS Software RSVP Denial of Service Vulnerability
Cisco IOS Software and Cisco IOS XE Software contain a vulnerability in the RSVP feature when used on a device configured with VPN routing and forwarding (VRF) instances. This vulnerability could allow an unauthenticated, remote attacker to cause an interface wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. This vulnerability could be exploited repeatedly to cause an extended DoS condition. A workaround is available to mitigate this vulnerability. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/
GHSA
GHSA-4wp8-c9m8-94qj: The RSVP feature in Cisco IOS 15
ghsa_unreviewed·2022-05-14
CVE-2012-1311 [HIGH] GHSA-4wp8-c9m8-94qj: The RSVP feature in Cisco IOS 15
The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/80692http://secunia.com/advisories/48611http://secunia.com/advisories/48621http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-rsvphttp://www.securityfocus.com/bid/52754http://www.securitytracker.com/id?1026865http://osvdb.org/80692http://secunia.com/advisories/48611http://secunia.com/advisories/48621http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-rsvphttp://www.securityfocus.com/bid/52754http://www.securitytracker.com/id?1026865
2012-03-29
Published