CVE-2012-3946
Cisco IOS < 15.3(2)S - Unauthenticated IPv6 ACL Bypass via Packet Drop Inconsistency
Title source: llmDescription
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
References (1)
Core 1
Core References
Release Notes x_refsource_confirm
http://www.cisco.com/c/en/us/td/docs/ios/15_3s/release/notes/15_3s_rel_notes/15_3s_caveats_15_3_2s.html
Scores
EPSS
0.0190
EPSS Percentile
77.4%
Details
CWE
CWE-264
Status
published
Products (1)
cisco/ios
< 15.3
Published
Apr 24, 2014
Tracked Since
Feb 18, 2026