CVE-2012-4661

Published Oct 29, 2012

Last updated a year ago

Overview

Description
Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 before 4.1(9) in Cisco Catalyst 6500 series switches and 7600 series routers might allow remote attackers to execute arbitrary code via a crafted DCERPC packet, aka Bug IDs CSCtr21359 and CSCtr27522.
Source
ykramarz@cisco.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
9
Impact score
9.5
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:P/A:C

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations