CVE-2012-3924

Cisco IOS 15.1-15.2 - Authenticated Denial of Service via SSLVPN with DTLS and PPPoA

Title source: llm
STIX 2.1

Description

The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78672

Scores

EPSS 0.0086
EPSS Percentile 54.6%

Details

Status published
Products (2)
cisco/ios 15.1
cisco/ios 15.2
Published Sep 16, 2012
Tracked Since Feb 18, 2026