CVE-2012-3923
Cisco IOS 12.4, 15.0, 15.1, 15.2 - Authenticated Denial of Service via SSLVPN with PPPoA Interface
Title source: llmDescription
The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.cisco.com/en/US/docs/ios/15_2m_and_t/release/notes/152-1TCAVS.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78670
Scores
EPSS
0.0086
EPSS Percentile
54.6%
Details
Status
published
Products (4)
cisco/ios
12.4
cisco/ios
15.0
cisco/ios
15.1
cisco/ios
15.2
Published
Sep 16, 2012
Tracked Since
Feb 18, 2026