CVE-2012-1314
published 2012-03-29CVE-2012-1314: The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.01%
78.8th percentile
The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit traffic, aka Bug ID CSCtt45381.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
vendor_cisco·2012-03-28·CVSS 7.8
CVE-2012-1312 [HIGH] Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
Cisco IOS Software contains a denial of service (DoS) vulnerability in the Wide Area Application Services (WAAS) Express feature that could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload.
Cisco IOS Software also contains a DoS vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature that could allow an unauthenticated, remote attacker to cause the router to reload.
An attacker could exploit these vulnerabilities by sending transit traffic through a router configured with WAAS Express or MACE. Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Repea
Cisco
Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
vendor_cisco
CVE-2012-1314 Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
CVE-2012-1314: Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
Cisco IOS Software contains a denial of service (DoS) vulnerability in the Wide Area Application Services (WAAS) Express feature that could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Cisco IOS Software also contains a DoS vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature that could allow an unauthenticated, remote attacker to cause the router to reload. An attacker could exploit these vulnerabilities by sending transit traffic through a router configured with WAAS Express or MACE. Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to cause the router to leak memory or to r
GHSA
GHSA-cc4g-rx68-59wj: The WAAS Express feature in Cisco IOS 15
ghsa_unreviewed·2022-05-14
CVE-2012-1314 [HIGH] GHSA-cc4g-rx68-59wj: The WAAS Express feature in Cisco IOS 15
The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit traffic, aka Bug ID CSCtt45381.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80702http://secunia.com/advisories/48595http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-macehttp://www.securityfocus.com/bid/52751http://www.securitytracker.com/id?1026862https://exchange.xforce.ibmcloud.com/vulnerabilities/74428http://osvdb.org/80702http://secunia.com/advisories/48595http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-macehttp://www.securityfocus.com/bid/52751http://www.securitytracker.com/id?1026862https://exchange.xforce.ibmcloud.com/vulnerabilities/74428
2012-03-29
Published