← Back

CVE-2012-5032

nvd nist
Published: Apr 23, 2014Modified: May 6, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

Affected (4)

Products: Cisco: Ios
1 product
Ios
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 15.1\(1\)sy2
Version 15.1
Version 15.1(1)sy1
Version 15.1(1)sy

Timeline

No history available yet.