CVE-2012-1338
published 2012-08-06CVE-2012-1338: Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing…
PriorityP426medium6.3CVSS 2.0
AVNACMAuSCNINAC
EPSS
1.09%
61.4th percentile
Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing local web authentication quickly, aka Bug ID CSCts88664.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pxf2-j48m-hx8c: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2012-1338 [MEDIUM] CWE-362 GHSA-pxf2-j48m-hx8c: Cisco IOS 15
Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing local web authentication quickly, aka Bug ID CSCts88664.
Cisco
Cisco IOS Authentication Request Processing Denial of Service Vulnerability
vendor_cisco·2012-08-23·CVSS 6.3
CVE-2012-1338 [MEDIUM] CWE-399 Cisco IOS Authentication Request Processing Denial of Service Vulnerability
Cisco IOS Authentication Request Processing Denial of Service Vulnerability
Cisco IOS contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of web authentication requests. An authenticated, remote attacker could exploit the vulnerability by sending malicious authentication requests to the affected software. Successful exploitation could cause a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit the vulnerability, authentication is required, and an attacker may require access to networks adjacent to a targeted device. These requirements increase the difficulty of exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/15.0_1_se/release/notes/OL25302.htmlhttp://www.securitytracker.com/id?1027349http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/15.0_1_se/release/notes/OL25302.htmlhttp://www.securitytracker.com/id?1027349
2012-08-06
Published