PT-2008-5166 · Cisco · Cisco Ios

Published

2008-09-24

·

Updated

2022-06-02

·

CVE-2008-3812

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS version 12.4
Description The issue allows remote attackers to cause a denial of service (device reload) via a malformed HTTP transit packet when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspection is enabled. Successful exploitation may result in a reload of the affected device.
Recommendations For Cisco IOS version 12.4, update to a version that includes the software updates released by Cisco to address this issue. As a temporary workaround, consider disabling the HTTP Deep Packet Inspection feature in the IOS firewall Application Inspection Control (AIC) until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-3812

Affected Products

Cisco Ios