Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.
Attack Vector Network
Attack Complexity Low
Privileges Required High
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:M/Au:S/C:C/I:C/A:C
Vendors | Products |
---|---|
Cisco |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Configuration 6 [-]
|
References
Link | Resource |
---|---|
http://osvdb.org/80704 | Broken Link |
http://secunia.com/advisories/48614 | Third Party Advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-pai | Vendor Advisory |
http://www.securityfocus.com/bid/52755 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id?1026860 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2012-03-29T10:00:00
Updated: 2012-06-28T09:00:00
Reserved: 2012-01-04T00:00:00
Link: CVE-2012-0384
JSON object: View
NVD Information
Status : Analyzed
Published: 2012-03-29T11:01:16.183
Modified: 2019-09-27T18:06:00.467
Link: CVE-2012-0384
JSON object: View
Redhat Information
No data.
CWE