CVE-2012-0386

Cisco IOS 12.2-15.2 and IOS XE 2.3.x-3.4.xS - Denial of Service via Reverse SSH Login Username

Title source: llm
STIX 2.1

Description

The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026866
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48609
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48641
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80695
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52752
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74404

Scores

EPSS 0.0312
EPSS Percentile 86.4%

Details

CWE
CWE-310
Status published
Products (34)
cisco/ios 12.2
cisco/ios 12.4
cisco/ios 15.0
cisco/ios 15.1
cisco/ios 15.2
cisco/ios_xe 2.3
cisco/ios_xe 2.3.0
cisco/ios_xe 2.3.1
cisco/ios_xe 2.3.1t
cisco/ios_xe 2.3.2
... and 24 more
Published Mar 29, 2012
Tracked Since Feb 18, 2026