CVE-2012-3946
published 2014-04-24CVE-2012-3946: Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.90%
77.5th percentile
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS 15.3 access control (Nessus ID 76346 / SBV-44284)
vuldb·2026-05-11·CVSS 5.0
CVE-2012-3946 [MEDIUM] Cisco IOS 15.3 access control (Nessus ID 76346 / SBV-44284)
A vulnerability, which was classified as critical, has been found in Cisco IOS 15.3. This issue affects some unknown processing. This manipulation causes improper access controls.
The identification of this vulnerability is CVE-2012-3946. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-6g2p-g3v6-8357: Cisco IOS before 15
ghsa_unreviewed·2022-05-17
CVE-2012-3946 [MEDIUM] GHSA-6g2p-g3v6-8357: Cisco IOS before 15
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-24
Published