Vulnerability Description
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2 |
| Cisco | Ios Xe | 2.1 |
Related Weaknesses (CWE)
References
- http://osvdb.org/80704Broken Link
- http://secunia.com/advisories/48614Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/52755Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026860Third Party AdvisoryVDB Entry
- http://osvdb.org/80704Broken Link
- http://secunia.com/advisories/48614Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/52755Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026860Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-0384?
CVE-2012-0384 is a vulnerability with a CVSS score of 7.2 (HIGH). Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2...
How severe is CVE-2012-0384?
CVE-2012-0384 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0384?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Ios Xe.