CVE-2012-3924
Cisco IOS 15.1-15.2 - Authenticated Denial of Service via SSLVPN with DTLS and PPPoA
Title source: llmDescription
The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.cisco.com/en/US/docs/ios/15_2m_and_t/release/notes/152-1TCAVS.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78672
Scores
EPSS
0.0086
EPSS Percentile
54.6%
Details
Status
published
Products (2)
cisco/ios
15.1
cisco/ios
15.2
Published
Sep 16, 2012
Tracked Since
Feb 18, 2026