5
CVSSv2

CVE-2019-12656

Published: 25/09/2019 Updated: 08/10/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote malicious user to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the malicious user to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 1.8.0

cisco ios 1.6.0.0

cisco industrial_ethernet_2000_series_firmware 15.2\\(6\\)e

cisco ic3000_firmware -

cisco ie_4000_firmware -

cisco cgr_1000_firmware -

cisco ir510_wpan_firmware -

Vendor Advisories

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition The vulnerability is due to a Transport Layer Security (TLS) implementation issue An attacker could exploit t ...