← Back to CVE List
Vulnerability Intelligence Report

CVE-2012-4661

Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 before 4.1(9) in Cisco Catalyst 6500 series switches and 7600 series routers might allow remote attackers to execute arbitrary code via a crafted DCERPC packet, aka Bug IDs CSCtr21359 and CSCtr27522.

No Active Exploit Signals
CVSS Base Score
9.0
HIGH
EPSS Probability:4.05%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
cisco adaptive_security_appliance_software 8.3\(1\), 8.3\(2\), 8.4, 8.4\(1\), 8.4\(1.11\), 8.4\(2\), 8.4\(2.11\), 8.5, 8.5\(1\), 8.5\(1.4\), 8.6, 8.6\(1\)
cisco 5500_series_adaptive_security_appliance all
cisco 7600_router all
cisco catalyst_6500 all
cisco catalyst_6503-e all
cisco catalyst_6504-e all
cisco catalyst_6506-e all
cisco catalyst_6509-e all
cisco catalyst_6509-neb-a all
cisco catalyst_6509-v-e all
cisco catalyst_6513 all
cisco catalyst_6513-e all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.047%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2012-08-24T00:00:00
Published2012-10-29T20:00:00
Patch Date2012-10-10
Last Updated2024-08-06T20:42:55

LINK COPIED TO CLIPBOARD