CVE-2019-12656
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/09/2019
Last modified:
08/10/2020
Description
A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cisco:ios:1.6.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:1.8.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:industrial_ethernet_2000_series_firmware:15.2\(6\)e:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16ptc-g:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16t67:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16t67p:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16tc:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16tc-g:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16tc-g-e:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16tc-g-n:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-16tc-g-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-24t67:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-4s-ts-g:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-4t:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:ie_2000-4t-g:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page