CVE-2012-5723
published 2014-04-24CVE-2012-5723: Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted…
PriorityP425medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.72%
50.1th percentile
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.7s\(.1\) | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS XE up to 3.6s input validation (SBV-45159 / BID-68242)
vuldb·2026-05-11·CVSS 6.1
CVE-2012-5723 [MEDIUM] Cisco IOS XE up to 3.6s input validation (SBV-45159 / BID-68242)
A vulnerability, which was classified as problematic, was found in Cisco IOS XE up to 3.6s. Impacted is an unknown function. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2012-5723. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-q7c6-x96r-hrg8: Cisco ASR 1000 devices with software before 3
ghsa_unreviewed·2022-05-13
CVE-2012-5723 [MEDIUM] CWE-20 GHSA-q7c6-x96r-hrg8: Cisco ASR 1000 devices with software before 3
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-24
Published