CVE-2012-3923

Cisco IOS 12.4, 15.0, 15.1, 15.2 - Authenticated Denial of Service via SSLVPN with PPPoA Interface

Title source: llm
STIX 2.1

Description

The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78670

Scores

EPSS 0.0086
EPSS Percentile 54.6%

Details

Status published
Products (4)
cisco/ios 12.4
cisco/ios 15.0
cisco/ios 15.1
cisco/ios 15.2
Published Sep 16, 2012
Tracked Since Feb 18, 2026