imPC@ndo IT

Tracker / CVE-2019-12656

CVE-2019-12656

High 7.5

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.

Affected products and versions

cisco cgr_1000_firmware
cisco ic3000_firmware
cisco ie_4000_firmware
cisco industrial_ethernet_2000_series_firmware
cisco ios
cisco ir510_wpan_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References