CVE-2012-1346
published 2012-08-06CVE-2012-1346: Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.23%
65.7th percentile
Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-frv7-4h3q-2j9h: Cisco Emergency Responder 8
ghsa_unreviewed·2022-05-17
CVE-2012-1346 [MEDIUM] GHSA-frv7-4h3q-2j9h: Cisco Emergency Responder 8
Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369.
Cisco
Cisco Emergency Responder Remote Denial of Service Vulnerability
vendor_cisco·2012-08-09·CVSS 5.0
CVE-2012-1346 [MEDIUM] CWE-399 Cisco Emergency Responder Remote Denial of Service Vulnerability
Cisco Emergency Responder Remote Denial of Service Vulnerability
Cisco Emergency Responder contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability is due to the improper handling of malformed UDP packets by the affected software. An unauthenticated, remote attacker could exploit this vulnerability by submitting malformed UDP packets to the vulnerable software. If successful, the attacker could cause a targeted device to consume excessive CPU resources, resulting in a DoS condition.
Cisco has confirmed this vulnerability and released software updates.
A successful exploit could allow an attacker to cause a device to stop responding, potentially preventing authorized users from acc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published