CVE-2012-4620
published 2012-09-27CVE-2012-4620: Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.75%
84.7th percentile
Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
vendor_cisco·2012-09-26·CVSS 7.8
CVE-2012-4620 [HIGH] CWE-399 Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
Cisco IOS Software contains a queue wedge vulnerability that can be triggered when processing IP tunneled packets. Only
Cisco IOS Software running on the Cisco 10000 Series router has
been demonstrated to be affected.
Successful exploitation of this vulnerability may prevent traffic from transiting the affected interfaces.
Cisco has released software updates that address this vulnerability. There are no workarounds for this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-c10k-tunnels
Note: The September 26, 2012, Cisco IOS Software Security Advisory bundled publication includes nine Cisco Security Advisories. Eigh
Cisco
Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
vendor_cisco
CVE-2012-4620 Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
CVE-2012-4620: Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability
Cisco IOS Software contains a queue wedge vulnerability that can be triggered when processing IP tunneled packets. Only Cisco IOS Software running on the Cisco 10000 Series router has been demonstrated to be affected. Successful exploitation of this vulnerability may prevent traffic from transiting the affected interfaces. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCts66808, CSCts66808
GHSA
GHSA-cqqf-42xp-fqpj: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2012-4620 [HIGH] GHSA-cqqf-42xp-fqpj: Cisco IOS 12
Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-c10k-tunnelshttp://www.securityfocus.com/bid/55696http://www.securitytracker.com/id?1027578https://exchange.xforce.ibmcloud.com/vulnerabilities/78883http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-c10k-tunnelshttp://www.securityfocus.com/bid/55696http://www.securitytracker.com/id?1027578https://exchange.xforce.ibmcloud.com/vulnerabilities/78883
2012-09-27
Published