CVE-2012-1344
published 2012-08-06CVE-2012-1344: Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
0.86%
54.7th percentile
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
vendor_cisco3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qh7f-gw68-jwqh: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2012-1344 [LOW] CWE-119 GHSA-qh7f-gw68-jwqh: Cisco IOS 15
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.
Cisco
Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
vendor_cisco·2012-08-10·CVSS 3.5
CVE-2012-1344 [LOW] CWE-399 Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability is due to an unspecified issue that causes a device running the vulnerable software to reload when the web browser reloads the SSL VPN portal page. An authenticated, remote attacker could exploit this vulnerability by using a web browser to refresh the SSL VPN portal page to cause the device to reload, resulting in a DoS condition. A successful exploit could deny services for legitimate users.
Cisco has confirmed this vulnerability and has released updated software.
A successful exploit would require an attacker to authenticate to a targeted devic
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published