NANOG
Threads by month
- ----- 2025 -----
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1998 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1997 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1996 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1995 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1994 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1993 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1992 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
March 2012
- 371 participants
- 169 discussions

Cisco Security Advisory: Cisco IOS Internet Key Exchange Vulnerability
by Cisco Systems Product Security Incident Response Team 28 Mar '12
by Cisco Systems Product Security Incident Response Team 28 Mar '12
28 Mar '12
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco Security Advisory: Cisco IOS Internet Key Exchange Vulnerability
Advisory ID: cisco-sa-20120328-ike
Revision 1.0
For Public Release 2012 March 28 16:00 UTC (GMT)
+--------------------------------------------------------------------
Summary
=======
The Cisco IOS Software Internet Key Exchange (IKE) feature contains a
denial of service (DoS) vulnerability.
Cisco has released free software updates that address this
vulnerability.
This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Note: The March 28, 2012, Cisco IOS Software Security Advisory
bundled publication includes nine Cisco Security Advisories. Each
advisory lists the Cisco IOS Software releases that correct the
vulnerability or vulnerabilities detailed in the advisory as well as
the Cisco IOS Software releases that correct all vulnerabilities in
the March 2012 bundled publication.
Individual publication links are in "Cisco Event Response:
Semi-Annual Cisco IOS Software Security Advisory Bundled Publication"
at the following link:
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar12.html
Affected Products
=================
Vulnerable Products
+------------------
Cisco devices that are running Cisco IOS Software are vulnerable when
they are configured to use IKE version 1 (IKEv1).
A number of features use IKEv1, including different Virtual Private
Networks (VPN) such as:
* LAN-to-LAN VPN
* Remote access VPN (excluding SSLVPN)
* Dynamic Multipoint VPN (DMVPN)
* Group Domain of Interpretation (GDOI)
There are two methods to determine if a device is configured for IKE:
* Determine if IKE ports are open on a running device
* Determine if IKE features are included in the device
configuration
Determine if IKE Ports are Open on a Running Device
+--------------------------------------------------
The preferred method to determine if a device has been configured for
IKE is to issue the "show ip sockets" or "show udp" exec command. If the
device has UDP port 500, UDP port 4500, UDP port 848, or UDP port 4848
open, it is processing IKE packets.
In the following example, the device is processing IKE packets in UDP
port 500 and UDP port 4500, using either IPv4 or IPv6:
router# show udp
Proto Remote Port Local Port In Out Stat TTY OutputIF
17 --listen-- 192.168.130.21 500 0 0 1001011 0
17(v6) --listen-- UNKNOWN 500 0 0 1020011 0
17 --listen-- 192.168.130.21 4500 0 0 1001011 0
17(v6) --listen-- UNKNOWN 4500 0 0 1020011 0
!--- Output truncated
router#
Determine if IKE Features are included in the Device Configuration
+-----------------------------------------------------------------
To determine if a Cisco IOS device configuration is vulnerable,
the administrator needs to establish whether there is at least one
configured feature that uses IKE. This can be achieved by using the
"show run | include crypto map|tunnel protection ipsec|crypto gdoi"
enable mode command. If the output of this command contains either
crypto map, tunnel protection ipsec, or, crypto gdoi then the device
contains an IKE configuration. The following example shows a device that
has been configured for IKE:
router# show run | include crypto map|tunnel protection ipsec|crypto gdoi
crypto map CM 100 ipsec-isakmp
crypto map CM
router#
Determine the Cisco IOS Software Release
+---------------------------------------
To determine the Cisco IOS Software release that is running on a Cisco
product, administrators can log in to the device and issue the "show
version" command to display the system banner. The system banner
confirms that the device is running Cisco IOS Software by displaying
text similar to "Cisco Internetwork Operating System Software" or "Cisco
IOS Software." The image name displays in parentheses, followed by
"Version" and the Cisco IOS Software release name. Other Cisco devices
do not have the "show version" command or may provide different output.
The following example identifies a Cisco product that is running
Cisco IOS Software Release 15.0(1)M1 with an installed image name of
C3900-UNIVERSALK9-M:
Router> show version
Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.0(1)M1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 02-Dec-09 17:17 by prod_rel_team
!--- output truncated
Additional information about Cisco IOS Software release naming
conventions is available in "White Paper: Cisco IOS and NX-OS
Software Reference Guide" at:
http://www.cisco.com/web/about/security/intelligence/ios-ref.html
Products Confirmed Not Vulnerable
+--------------------------------
Cisco ASA 5500 Series Adaptive Security Appliance is not affected by
this vulnerability.
No other Cisco products are currently known to be affected by this
vulnerability.
Details
=======
The IKE protocol is used in the Internet Protocol Security (IPsec)
protocol suite to negotiate cryptographic attributes that will be
used to encrypt or authenticate the communication session. These
attributes include cryptographic algorithm, mode, and shared keys.
The end result of IKE is a shared session secret that will be used to
derive cryptographic keys.
Cisco IOS Software supports IKE for IPv4 and IPv6 communications.
IKE communication can use any of the following UDP ports:
* UDP port 500
* UDP port 4500, NAT Traversal (NAT-T)
* UDP port 848, Group Domain of Interpretation (GDOI)
* UDP port 4848, GDOI NAT-T
The IKEv1 feature of Cisco IOS Software contains a vulnerability that
could allow an unauthenticated, remote attacker to cause a reload of
an affected device.
An attacker could exploit this vulnerability using either IPv4 or
IPv6 on any of the listed UDP ports. Spoofing of packets that could
exploit this vulnerability is limited because the attacker needs to
either receive or have access to the initial response from the
vulnerable device.
This vulnerability is documented in Cisco bug ID CSCts38429 and has been
assigned Common Vulnerabilities and Exposures (CVE) ID CVE-2012-0381.
Vulnerability Scoring Details
=============================
Cisco has scored the vulnerabilities in this advisory based on the
Common Vulnerability Scoring System (CVSS). The CVSS scoring in this
security advisory is in accordance with CVSS version 2.0.
CVSS is a standards-based scoring method that conveys vulnerability
severity and helps organizations determine the urgency and priority
of a response.
Cisco has provided a base and temporal score. Customers can also
compute environmental scores that help determine the impact of the
vulnerability in their own networks.
Cisco has provided additional information regarding CVSS at the
following link:
http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html
Cisco has also provided a CVSS calculator to compute the
environmental impact for individual networks at the following link:
http://intellishield.cisco.com/security/alertmanager/cvss
* CSCts38429 ("Cisco IOS Software IKE DoS vulnerability")
CVSS Base Score - 7.8
Access Vector - Network
Access Complexity - Low
Authentication - None
Confidentiality Impact - None
Integrity Impact - None
Availability Impact - Complete
CVSS Temporal Score - 6.4
Exploitability - Functional
Remediation Level - Official-Fix
Report Confidence - Confirmed
Impact
======
Successful exploitation of the vulnerability may cause the vulnerable
device to reload.
Software Versions and Fixes
===========================
Cisco IOS Software
+-----------------
Each row of the following Cisco IOS Software table corresponds to a
Cisco IOS Software train. If a particular train is vulnerable, the
earliest releases that contain the fix are listed in the First Fixed
Release column. The First Fixed Release for All Advisories in the
March 2012 Bundled Publication column lists the earliest possible
releases that correct all the published vulnerabilities in the Cisco
IOS Software Security Advisory bundled publication. Cisco recommends
upgrading to the latest available release, where possible.
The Cisco IOS Software Checker allows customers to search for Cisco
Security Advisories that address specific Cisco IOS Software
releases. This tool is available on the Cisco Security Intelligence
Operations (SIO) portal at:
http://tools.cisco.com/security/center/selectIOSVersion.x
+-------------------------------------------------------------------+
| Major | Availability of Repaired Releases |
| Release | |
|----------+--------------------------------------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|12.0-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|-------------------------------------------------------------------|
| There are no affected 12.0 based releases |
|-------------------------------------------------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|12.2-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|12.2 |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0M |Vulnerable; First fixed in |
|12.2B |Releases up to and including|Release 15.0M |
| |12.2(2)B7 are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0M |Vulnerable; First fixed in |
|12.2BC |Releases up to and including|Release 15.0M |
| |12.2(4)BC1b are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
|12.2BW |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 12.2SRE |Vulnerable; First fixed in |
|12.2BX |Releases up to and including|Release 12.2SB |
| |12.2(2)BX1 are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0M |Vulnerable; First fixed in |
|12.2BY |Releases up to and including|Release 15.0M |
| |12.2(2)BY3 are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0M |Vulnerable; First fixed in |
|12.2BZ |Releases up to and including|Release 15.0M |
| |12.2(4)BZ2 are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
|12.2CX |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2CY |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2CZ |Vulnerable; migrate to any |Vulnerable; First fixed in |
| |release in 12.0S |Release 12.0S |
|----------+----------------------------+---------------------------|
|12.2DA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2DD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2DX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2EU |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2EW |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2EWA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2EX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2EY |Not vulnerable |12.2(52)EY4 |
|----------+----------------------------+---------------------------|
|12.2EZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2FX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2FY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2FZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2IRA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2IRB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2IRC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2IRD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2IRE |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2IRF |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IRG |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IRH |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXB |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXD |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXE |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXF |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXG |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2IXH |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2JA |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
|12.2JK |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
|12.2MB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2MC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2MRA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2MRB |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Note: Releases prior to 12.2|Releases prior to 12.2(30)S|
| |(25)S1 are vulnerable; |are vulnerable; Releases |
|12.2S |Releases 12.2(25)S1 and |12.2(30)S and later are not|
| |later are not vulnerable. |vulnerable. First fixed in |
| | |Release 12.0S |
|----------+----------------------------+---------------------------|
| |Only releases 12.2(33)SB1 | |
|12.2SB |through 12.2(33)SB4 are |12.2(33)SB12 |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
|12.2SBC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2SCA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SCE |Release 12.2SCE |
|----------+----------------------------+---------------------------|
|12.2SCB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SCE |Release 12.2SCE |
|----------+----------------------------+---------------------------|
|12.2SCC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SCE |Release 12.2SCE |
|----------+----------------------------+---------------------------|
|12.2SCD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SCE |Release 12.2SCE |
|----------+----------------------------+---------------------------|
|12.2SCE |12.2(33)SCE6 |12.2(33)SCE6 |
|----------+----------------------------+---------------------------|
|12.2SCF |12.2(33)SCF2 |12.2(33)SCF2 |
|----------+----------------------------+---------------------------|
|12.2SE |Not vulnerable* | |
| | |12.2(55)SE5 * |
|----------+----------------------------+---------------------------|
|12.2SEA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SEB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SEC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SED |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SEE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SEF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SEG |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+----------------------------+---------------------------|
|12.2SG |Not vulnerable |12.2(53)SG7; Available on |
| | |07-MAY-12 |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SGA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2SL |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SM |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SO |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SQ |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2SRA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2SRB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2SRC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRD |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2SRD |12.2(33)SRD8 |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.2SRE |12.2(33)SRE6 |12.2(33)SRE6 |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2STE |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2SU |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |Releases up to and |
|12.2SV |Not vulnerable |including 12.2(18)SV2 are |
| | |not vulnerable. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SVA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SVC |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SVD |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2SVE |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Releases up to and including| |
| |12.2(21)SW1 are not | |
|12.2SW |vulnerable. |Vulnerable; First fixed in |
| |Releases 12.2(25)SW10 and |Release 12.4T |
| |later are not vulnerable. | |
| |First fixed in Release 12.4T| |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SX |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXB |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXD |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXE |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXF |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2SXH |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2SXI |12.2(33)SXI9 |12.2(33)SXI9 |
|----------+----------------------------+---------------------------|
|12.2SXJ |12.2(33)SXJ2 |12.2(33)SXJ2 |
|----------+----------------------------+---------------------------|
|12.2SY |12.2(50)SY2; Available on |12.2(50)SY2; Available on |
| |11-JUN-12 |11-JUN-12 |
|----------+----------------------------+---------------------------|
|12.2SZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.0S |
|----------+----------------------------+---------------------------|
|12.2T |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2TPC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2XA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XE |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XG |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XH |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XI |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XJ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XK |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XL |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XM |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XNA |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
|12.2XNB |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
|12.2XNC |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
|12.2XND |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
|12.2XNE |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
|12.2XNF |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2XO |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2XQ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |Releases prior to 12.2(15) |
| | |XR are vulnerable; Releases|
|12.2XR |Not vulnerable |12.2(15)XR and later are |
| | |not vulnerable. First fixed|
| | |in Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XS |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XT |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XU |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XV |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2XW |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2YA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YD |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YE |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2YK |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YO |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; First fixed in |
| | |Release 15.0M |
|12.2YP |Not vulnerable |Releases up to and |
| | |including 12.2(8)YP are not|
| | |vulnerable. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2YT |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YW |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YX |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YY |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2YZ |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| |Releases up to and including|support organization per |
|12.2ZB |12.2(8)ZB are not |the instructions in |
| |vulnerable. |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2ZC |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZD |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2ZE |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.2ZH |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZJ |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.2ZP |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZU |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.2ZX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZY |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.2ZYA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|12.3-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|12.3 |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3B |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3BC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SCE |Release 12.2SCE |
|----------+----------------------------+---------------------------|
|12.3BW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3JA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4JA |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.3JEA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.3JEB |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3JEC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3JED |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Releases up to and including| |
| |12.3(2)JK3 are not | |
|12.3JK |vulnerable. |Vulnerable; First fixed in |
| |Releases 12.3(8)JK1 and |Release 15.0M |
| |later are not vulnerable. | |
| |First fixed in Release 15.0M| |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.3JL |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.3JX |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
|12.3T |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3TPC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.3VA |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
|12.3XA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3XB |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.3XC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XE |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3XF |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.3XG |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XI |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.2SRE |Release 12.2SRE |
|----------+----------------------------+---------------------------|
|12.3XJ |Vulnerable; migrate to any |Vulnerable; First fixed in |
| |release in 12.4XN |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XK |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XL |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XQ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XR |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; First fixed in | |
| |Release 12.4T |Vulnerable; First fixed in |
|12.3XU |Releases up to and including|Release 12.4T |
| |12.3(8)XU1 are not | |
| |vulnerable. | |
|----------+----------------------------+---------------------------|
|12.3XW |Vulnerable; migrate to any |Vulnerable; First fixed in |
| |release in 12.4XN |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XX |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3XZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YF |Vulnerable; migrate to any |Vulnerable; First fixed in |
| |release in 12.4XN |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YG |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YI |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YJ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YK |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YM |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YQ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YS |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YT |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YU |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.3YX |Vulnerable; migrate to any |Vulnerable; First fixed in |
| |release in 12.4XN |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.3YZ |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.3ZA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|12.4-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|12.4 |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.0M |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4GC |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4JA |Not vulnerable |12.4(23c)JA4 |
| | |12.4(25e)JA |
|----------+----------------------------+---------------------------|
|12.4JAX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4JA |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JDA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JDC |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JDD |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JDE |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JHA |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JHB |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JHC |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JK |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4JL |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4JX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4JA |
|----------+----------------------------+---------------------------|
|12.4JY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4JA |
|----------+----------------------------+---------------------------|
|12.4JZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4JA |
|----------+----------------------------+---------------------------|
|12.4MD |12.4(22)MD3; Available on |12.4(22)MD3; Available on |
| |30-MAR-12 |30-MAR-12 |
|----------+----------------------------+---------------------------|
|12.4MDA |12.4(24)MDA11 |12.4(24)MDA11 |
|----------+----------------------------+---------------------------|
|12.4MDB |12.4(24)MDB5a |12.4(24)MDB5a |
|----------+----------------------------+---------------------------|
|12.4MDC |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| |Releases up to and including|support organization per |
|12.4MR |12.4(9)MR are not |the instructions in |
| |vulnerable. |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4MRA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4MRB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4SW |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| |12.4(15)T17 |12.4(15)T17 |
|12.4T |12.4(24)T7 |12.4(24)T7 |
| | | |
|----------+----------------------------+---------------------------|
|12.4XA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Releases prior to 12.4(2) | |
| |XB12 are vulnerable; |Vulnerable; First fixed in |
|12.4XB |Releases 12.4(2)XB12 and |Release 12.4T |
| |later are not vulnerable. | |
| |First fixed in Release 12.4T| |
|----------+----------------------------+---------------------------|
|12.4XC |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XD |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XE |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XF |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XG |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XJ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XK |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4XL |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4XM |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+----------------------------+---------------------------|
| | |Vulnerable; contact your |
| | |support organization per |
|12.4XN |Not vulnerable |the instructions in |
| | |Obtaining Fixed Software |
| | |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4XP |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4XQ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XR |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 12.4T |
|----------+----------------------------+---------------------------|
|12.4XT |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4XV |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4XW |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XY |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4XZ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
|12.4YA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4YB |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|12.4YD |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|12.4YE |12.4(24)YE3d |12.4(24)YE3d |
|----------+----------------------------+---------------------------|
|12.4YG |12.4(24)YG4 |12.4(24)YG4 |
|----------+----------------------------+---------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|15.0-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|15.0M |15.0(1)M8 |15.0(1)M8 |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|15.0MR |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|15.0MRA |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |15.0(1)S5 |15.0(1)S5 |
|15.0S |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
| |see Cisco IOS XE Software |Please see Cisco IOS XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
|15.0SA |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
|15.0SE |Not vulnerable |15.0(1)SE1 |
|----------+----------------------------+---------------------------|
| |Not vulnerable |15.0(2)SG2 |
|15.0SG |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
| |see Cisco IOS XE Software |Please see Cisco IOS XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
|15.0SY |15.0(1)SY1 |15.0(1)SY1 |
|----------+----------------------------+---------------------------|
|15.0XA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.1T |Release 15.1T |
|----------+----------------------------+---------------------------|
| |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
|15.0XO |see Cisco IOS-XE Software |Please see Cisco IOS-XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|15.1-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|15.1EY |Not vulnerable |15.1(2)EY2 |
|----------+----------------------------+---------------------------|
|15.1GC |15.1(2)GC2 |15.1(2)GC2 |
|----------+----------------------------+---------------------------|
|15.1M |15.1(4)M3 |15.1(4)M4; Available on |
| | |30-MAR-12 |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|15.1MR |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
| |15.1(3)S2 |15.1(3)S2 |
|15.1S |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
| |see Cisco IOS XE Software |Please see Cisco IOS XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
| |Not vulnerable |Not vulnerable |
|15.1SG |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
| |see Cisco IOS XE Software |Please see Cisco IOS XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per the|support organization per |
|15.1SNG |instructions in Obtaining |the instructions in |
| |Fixed Software section of |Obtaining Fixed Software |
| |this advisory. |section of this advisory. |
|----------+----------------------------+---------------------------|
|15.1SNH |Not vulnerable |Not vulnerable |
|----------+----------------------------+---------------------------|
| |15.1(1)T5; Available on | |
| |18-MAY-12 | |
|15.1T |15.1(2)T5; Available on |15.1(3)T3 |
| |27-APR-12 | |
| |15.1(3)T3 | |
|----------+----------------------------+---------------------------|
|15.1XB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.1T |Release 15.1T |
|----------+----------------------------+---------------------------|
| | |First Fixed Release for All|
| Affected | | Advisories in the March |
|15.2-Based| First Fixed Release | 2012 Cisco IOS Software |
| Releases | | Security Advisory Bundled |
| | | Publication |
|----------+----------------------------+---------------------------|
|15.2GC |15.2(1)GC2 |15.2(1)GC2 |
|----------+----------------------------+---------------------------|
| |15.2(1)S1 |15.2(1)S1 |
| | | |
|15.2S |Cisco IOS XE devices: Please|Cisco IOS XE devices: |
| |see Cisco IOS XE Software |Please see Cisco IOS XE |
| |Availability |Software Availability |
|----------+----------------------------+---------------------------|
| |15.2(1)T2 |15.2(1)T2 |
|15.2T |15.2(2)T1 |15.2(2)T1 |
| |15.2(3)T; Available on |15.2(3)T; Available on |
| |30-MAR-12 |30-MAR-12 |
+-------------------------------------------------------------------+
* Cisco Catalyst 3550 Series Switches support the Internet Key
Exchange (IKE) feature and are vulnerable to Cisco bug ID CSCts38429
when the devices are running Layer 3 images; however, this product
reached the End of Software Maintenance milestone. Cisco 3550 Series
SMI Switches that are running Layer 2 images do not support IKE and
are not vulnerable. No other Cisco devices that run 12.2SE-based
software are vulnerable.
Cisco IOS XE Software
+--------------------
+------------------------------------------------------------+
| Cisco IOS | | First Fixed Release for All |
| XE | First Fixed | Advisories in the March 2012 |
| Software | Release | Cisco IOS Software Security |
| Release | | Advisory Bundled Publication |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.1.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.2.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.3.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.4.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.5.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 2.6.x | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 3.1.xS | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| 3.1.xSG | Not | Vulnerable; migrate to 3.2.2SG |
| | vulnerable | or later. |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 3.2.xS | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| 3.2.xSG | 3.2.2SG | 3.2.2SG |
|-----------+--------------+---------------------------------|
| | Vulnerable; | |
| 3.3.xS | migrate to | Vulnerable; migrate to 3.4.2S |
| | 3.4.2S or | or later. |
| | later. | |
|-----------+--------------+---------------------------------|
| 3.3.xSG | Not | Not Vulnerable |
| | Vulnerable | |
|-----------+--------------+---------------------------------|
| 3.4.xS | 3.4.2S | 3.4.2S |
|-----------+--------------+---------------------------------|
| 3.5.xS | 3.5.1S | 3.5.1S |
|-----------+--------------+---------------------------------|
| 3.6.xS | Not | Not vulnerable |
| | vulnerable | |
+------------------------------------------------------------+
For a mapping of Cisco IOS XE Software releases to Cisco IOS Software
releases, refer to Cisco IOS XE 2 Release Notes, Cisco IOS XE 3S
Release Notes, and Cisco IOS XE 3SG Release Notes.
Cisco IOS XR Software
+--------------------
Cisco IOS XR Software is not affected by any of the vulnerabilities
disclosed in the March 2012 Cisco IOS Software Security Advisory
Bundled Publication.
Workarounds
===========
There are no workarounds for this vulnerability.
Obtaining Fixed Software
========================
Cisco has released free software updates that address the
vulnerability described in this advisory. Prior to deploying
software, customers are advised to consult their maintenance
providers or check the software for feature set compatibility and
known issues that are specific to their environments.
Customers may only install and expect support for feature
sets they have purchased. By installing, downloading,
accessing, or otherwise using such software upgrades, customers
agree to follow the terms of the Cisco software license at
http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html,
or as set forth at
http://www.cisco.com/public/sw-center/sw-usingswc.shtml.
Do not contact psirt(a)cisco.com or security-alert(a)cisco.com for
software upgrades.
Customers with Service Contracts
+-------------------------------
Customers with contracts should obtain upgraded software through their
regular update channels. For most customers, upgrades should be obtained
through the Software Center on Cisco.com at http://www.cisco.com.
Customers Using Third-Party Support Organizations
+------------------------------------------------
Customers with Cisco products that are provided or maintained through
prior or existing agreements with third-party support organizations,
such as Cisco Partners, authorized resellers, or service providers,
should contact that organization for assistance with the appropriate
course of action.
The effectiveness of any workaround or fix depends on specific
customer situations, such as product mix, network topology, traffic
behavior, and organizational mission. Because of the variety of
affected products and releases, customers should consult their
service providers or support organizations to ensure that any applied
workaround or fix is the most appropriate in the intended network
before it is deployed.
Customers Without Service Contracts
+----------------------------------
Customers who purchase directly from Cisco but do not hold a Cisco
service contract and customers who make purchases through third-party
vendors but are unsuccessful in obtaining fixed software through
their point of sale should obtain upgrades by contacting the Cisco
Technical Assistance Center (TAC):
* +1 800 553 2447 (toll free from within North America)
* +1 408 526 7209 (toll call from anywhere in the world)
* e-mail: tac(a)cisco.com
Customers should have the product serial number available and be
prepared to provide the URL of this advisory as evidence of
entitlement to a free upgrade. Customers without service contracts
should request free upgrades through the TAC.
Refer to Cisco Worldwide Contacts at
http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html
for additional TAC contact information, including localized telephone
numbers, instructions, and e-mail addresses for support in various
languages.
Exploitation and Public Announcements
=====================================
The Cisco Product Security Incident Response Team (PSIRT) is not
aware of any public announcements or malicious use of the
vulnerability that is described in this advisory.
This vulnerability was found during internal Cisco testing.
Status of This Notice: Final
============================
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY
KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE
INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS
AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS
DOCUMENT AT ANY TIME.
A stand-alone copy or Paraphrase of the text of this document that
omits the distribution URL in the following section is an
uncontrolled copy, and may lack important information or contain
factual errors.
Distribution
============
This advisory is posted on Cisco Security Intelligence Operations at
the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Additionally, a text version of this advisory is clear signed with
the Cisco PSIRT PGP key and circulated among the following e-mail
addresses:
* cust-security-announce(a)cisco.com
* first-bulletins(a)lists.first.org
* bugtraq(a)securityfocus.com
* vulnwatch(a)vulnwatch.org
* cisco(a)spot.colorado.edu
* cisco-nsp(a)puck.nether.net
* full-disclosure(a)lists.grok.org.uk
Future updates of this advisory, if any, will reside on Cisco.com but
may not be announced on mailing lists. Users can monitor this
advisory's URL for any updates.
Revision History
================
+------------------------------------------------------------+
| Revision 1.0 | 2012-March-28 | Initial public release. |
+------------------------------------------------------------+
Cisco Security Procedures
=========================
Complete information about reporting security vulnerabilities in Cisco
products, obtaining assistance with security incidents, and registering
to receive security information from Cisco is available on Cisco.com at
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.….
This web page includes instructions for press inquiries
regarding Cisco Security Advisories. All Cisco Security Advisories are
available at http://www.cisco.com/go/psirt.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iF4EAREIAAYFAk9xNMgACgkQQXnnBKKRMND8jwD6AzE8IxsF7PzqGh9w75+OhEQ7
z3dm7J1xzgPKLxtI7R8A/1AXDWCmSXsfNHJjhTPmMeZ5kxiA+9AfvxkWJLWxDMZ2
=sT/L
-----END PGP SIGNATURE-----
1
0

Cisco Security Advisory: Cisco IOS Software Reverse SSH Denial of Service Vulnerability
by Cisco Systems Product Security Incident Response Team 28 Mar '12
by Cisco Systems Product Security Incident Response Team 28 Mar '12
28 Mar '12
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco Security Advisory: Cisco IOS Software Reverse SSH Denial of Service Vulnerability
Advisory ID: cisco-sa-20120328-ssh
Revision 1.0
For Public Release 2012 March 28 16:00 UTC (GMT)
+---------------------------------------------------------------------
Summary
=======
The Secure Shell (SSH) server implementation in Cisco IOS Software
and Cisco IOS XE Software contains a denial of service (DoS)
vulnerability in the SSH version 2 (SSHv2) feature. An
unauthenticated, remote attacker could exploit this vulnerability by
attempting a reverse SSH login with a crafted username. Successful
exploitation of this vulnerability could allow an attacker to create
a DoS condition by causing the device to reload. Repeated exploits
could create a sustained DoS condition.
The SSH server in Cisco IOS Software and Cisco IOS XE Software is an
optional service, but its use is highly recommended as a security
best practice for the management of Cisco IOS devices. Devices that
are not configured to accept SSHv2 connections are not affected by
this vulnerability.
Cisco has released free software updates that address this
vulnerability. This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Note: The March 28, 2012, Cisco IOS Software Security Advisory
bundled publication includes nine Cisco Security Advisories. Each
advisory lists the Cisco IOS Software releases that correct the
vulnerability or vulnerabilities detailed in the advisory as well as
the Cisco IOS Software releases that correct all vulnerabilities in
the March 2012 bundled publication.
Individual publication links are in "Cisco Event Response:
Semi-Annual Cisco IOS Software Security Advisory Bundled Publication"
at the following link:
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar12.html
Affected Products
=================
Vulnerable Products
+------------------
Cisco devices that are running affected Cisco IOS Software or Cisco
IOS XE Software versions are vulnerable when they have the SSH server
enabled and allow SSHv2 logins. Only SSHv2 is affected.
To determine if SSH is enabled, use the show ip ssh command.
Router#show ip ssh
SSH Enabled - version 2.0
Authentication timeout: 120 secs; Authentication retries: 3
The previous output shows that SSH is enabled on this device and that
the SSH protocol major version that is being supported is 2.0.
Possible values for the SSH protocol versions that are reported by
Cisco IOS are:
* 1.5: only SSH protocol version 1 is enabled
* 1.99: SSH protocol version 2 with SSH protocol version 1
compatibility enabled
* 2.0: only SSH protocol version 2 is enabled
The SSH server is not available in all IOS images. If the show ip ssh
command is not available, the device is not vulnerable. Devices that
do not support SSHv2 are not vulnerable.
To determine the Cisco IOS Software release that is running on a
Cisco product, administrators can log in to the device and issue the
show version command to display the system banner. The system banner
confirms that the device is running Cisco IOS Software by displaying
text similar to "Cisco Internetwork Operating System Software" or
"Cisco IOS Software." The image name displays in parentheses,
followed by "Version" and the Cisco IOS Software release name. Other
Cisco devices do not have the show version command or may provide
different output.
The following example identifies a Cisco product that is running
Cisco IOS Software Release 15.0(1)M1 with an installed image name of
C3900-UNIVERSALK9-M:
Router> show version
Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.0(1)M1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 02-Dec-09 17:17 by prod_rel_team
!--- output truncated
Additional information about Cisco IOS Software release naming
conventions is available in "White Paper: Cisco IOS and NX-OS
Software Reference Guide" at:
http://www.cisco.com/web/about/security/intelligence/ios-ref.html
Products Confirmed Not Vulnerable
+--------------------------------
Cisco IOS-XR is not affected by this vulnerability.
No other Cisco products are currently known to be affected by this
vulnerability.
Details
=======
Secure Shell (SSH) is a protocol which provides a secure remote
access connection to network devices.
The SSH server implementation in Cisco IOS Software and Cisco IOS XE
Software contains a DoS vulnerability in the SSH version 2 (SSHv2)
feature that could allow an unauthenticated remote attacker to cause
a device to reload. An attacker could exploit this vulnerability by
attempting a reverse SSH login with a crafted username. Successful
exploitation of this vulnerability could allow an attacker to create
a DoS condition by causing the device to reload. Repeated exploits
could create a sustained DoS condition.
The SSH server in Cisco IOS Software and Cisco IOS XE Software is an
optional service, but its use is highly recommended as a security
best practice for management of Cisco IOS devices. SSH can be
configured as part of the AutoSecure feature in the initial
configuration of IOS devices, AutoSecure run after initial
configuration, or manually. SSH is enabled any time RSA keys are
generated such as when an http secure-server or trust points for
digital certificates are configured. Devices that are not configured
to accept SSHv2 connections are not affected by this vulnerability.
A complete TCP three-way handshake is required to exploit this
vulnerability. Reverse SSH traffic uses TCP port 22 by default.
This vulnerability has been documented in Cisco Bug ID CSCtr49064 and
has been assigned the Common Vulnerabilities and Exposures (CVE) ID
CVE-2012-0386.
Vulnerability Scoring Details
=============================
Cisco has scored the vulnerability in this advisory based on the
Common Vulnerability Scoring System (CVSS). The CVSS scoring in this
security advisory is in accordance with CVSS version 2.0.
CVSS is a standards-based scoring method that conveys vulnerability
severity and helps organizations determine the urgency and priority
of a response.
Cisco has provided a base and temporal score. Customers can also
compute environmental scores that help determine the impact of the
vulnerability in their own networks.
Cisco has provided additional information regarding CVSS at the
following link:
http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html
Cisco has also provided a CVSS calculator to compute the
environmental impact for individual networks at the following link:
http://intellishield.cisco.com/security/alertmanager/cvss
* CSCtr49064 - Cisco IOS Software Reverse SSH Denial of Service
CVSS Base Score - 7.8
Access Vector - Network
Access Complexity - Low
Authentication - None
Confidentiality Impact - None
Integrity Impact - None
Availability Impact - Complete
CVSS Temporal Score - 6.4
Exploitability - Functional
Remediation Level - Official-Fix
Report Confidence - Confirmed
Impact
======
Successful exploitation of this vulnerability could allow an
unauthenticated, remote attacker to create a DoS condition by causing
the device to reload. Repeated exploits could create a sustained DoS
condition.
Software Versions and Fixes
===========================
When considering software upgrades, customers are advised to consult
the Cisco Security Advisories and Responses archive at:
http://www.cisco.com/go/psirt and review subsequent advisories to determine
exposure and a complete upgrade solution.
In all cases, customers should ensure that the devices to be upgraded
contain sufficient memory and confirm that current hardware and
software configurations will continue to be supported properly by the
new release. If the information is not clear, customers are advised
to contact the Cisco Technical Assistance Center (TAC) or their
contracted maintenance providers.
Cisco IOS Software
+-----------------
Each row of the following Cisco IOS Software table corresponds to a
Cisco IOS Software train. If a particular train is vulnerable, the
earliest releases that contain the fix are listed in the First Fixed
Release column. The First Fixed Release for All Advisories in the
March 2012 Bundled Publication column lists the earliest possible
releases that correct all the published vulnerabilities in the Cisco
IOS Software Security Advisory bundled publication. Cisco recommends
upgrading to the latest available release, where possible.
The Cisco IOS Software Checker allows customers to search for Cisco
Security Advisories that address specific Cisco IOS Software
releases. This tool is available on the Cisco Security Intelligence
Operations (SIO) portal at:
http://tools.cisco.com/security/center/selectIOSVersion.x
+-------------------------------------------------------------------+
| Major | Availability of Repaired Releases |
| Release | |
|----------+--------------------------------------------------------|
| Affected | |First Fixed Release for All |
|12.0-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|-------------------------------------------------------------------|
| There are no affected 12.0 based releases |
|-------------------------------------------------------------------|
| Affected | |First Fixed Release for All |
|12.2-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|----------+---------------------------+----------------------------|
|12.2 |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2B |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2BC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2BW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2BX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SB |
|----------+---------------------------+----------------------------|
|12.2BY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2BZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2CX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2CY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2CZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.0S |
|----------+---------------------------+----------------------------|
|12.2DA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2DD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2DX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2EU |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2EW |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2EWA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0SE |Vulnerable; First fixed in |
|12.2EX |Releases up to and |Release 15.0SE |
| |including 12.2(55)EX3 are | |
| |not vulnerable. | |
|----------+---------------------------+----------------------------|
|12.2EY |12.2(58)EY2 |12.2(52)EY4 |
|----------+---------------------------+----------------------------|
|12.2EZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2FX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2FY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2FZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2IRA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2IRB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2IRC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2IRD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2IRE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2IRF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IRG |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IRH |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXB |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXC |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXD |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXE |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXF |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXG |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2IXH |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2JA |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
|12.2JK |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
|12.2MB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2MC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2MRA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2MRB |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Releases prior to 12.2(30)S |
| | |are vulnerable; Releases |
|12.2S |Not vulnerable |12.2(30)S and later are not |
| | |vulnerable. First fixed in |
| | |Release 12.0S |
|----------+---------------------------+----------------------------|
|12.2SB |Not vulnerable |12.2(33)SB12 |
|----------+---------------------------+----------------------------|
|12.2SBC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2SCA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SCE |
|----------+---------------------------+----------------------------|
|12.2SCB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SCE |
|----------+---------------------------+----------------------------|
|12.2SCC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SCE |
|----------+---------------------------+----------------------------|
|12.2SCD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SCE |
|----------+---------------------------+----------------------------|
|12.2SCE |Not vulnerable |12.2(33)SCE6 |
|----------+---------------------------+----------------------------|
|12.2SCF |Not vulnerable |12.2(33)SCF2 |
|----------+---------------------------+----------------------------|
| |Vulnerable; First fixed in | |
| |Release 15.0SE | |
|12.2SE |Releases up to and |12.2(55)SE5 * |
| |including 12.2(58)SE1 are | |
| |not vulnerable. | |
|----------+---------------------------+----------------------------|
|12.2SEA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SEB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SEC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SED |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SEE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SEF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SEG |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0SE |
|----------+---------------------------+----------------------------|
|12.2SG |Not vulnerable |12.2(53)SG7; Available on |
| | |07-MAY-12 |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SGA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2SL |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SM |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SO |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SQ |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2SRA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2SRB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2SRC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2SRD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
|12.2SRE |Not vulnerable |12.2(33)SRE6 |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2STE |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2SU |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Releases up to and including|
|12.2SV |Not vulnerable |12.2(18)SV2 are not |
| | |vulnerable. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SVA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SVC |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SVD |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SVE |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2SW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4T |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SX |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXB |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXD |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXE |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXF |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2SXH |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2SXI |Not vulnerable |12.2(33)SXI9 |
|----------+---------------------------+----------------------------|
|12.2SXJ |Not vulnerable |12.2(33)SXJ2 |
|----------+---------------------------+----------------------------|
|12.2SY |Not vulnerable |12.2(50)SY2; Available on |
| | |11-JUN-12 |
|----------+---------------------------+----------------------------|
|12.2SZ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.0S |
|----------+---------------------------+----------------------------|
|12.2T |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2TPC |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2XA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XG |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XH |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XI |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XJ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XK |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XL |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XM |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XNA |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
|12.2XNB |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
|12.2XNC |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
|12.2XND |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
|12.2XNE |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
|12.2XNF |Please see Cisco IOS-XE |Please see Cisco IOS-XE |
| |Software Availability |Software Availability |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2XO |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2XQ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Releases prior to 12.2(15)XR|
| | |are vulnerable; Releases |
|12.2XR |Not vulnerable |12.2(15)XR and later are not|
| | |vulnerable. First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XS |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XT |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XU |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XV |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2XW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2YA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YC |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YD |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YE |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YK |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YO |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; First fixed in |
| | |Release 15.0M |
|12.2YP |Not vulnerable |Releases up to and including|
| | |12.2(8)YP are not |
| | |vulnerable. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YT |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YW |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YX |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YY |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2YZ |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZB |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZC |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZD |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2ZE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.2ZH |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZJ |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZP |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZU |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.2ZX |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.2SRE |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZY |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.2ZYA |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| Affected | |First Fixed Release for All |
|12.3-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|-------------------------------------------------------------------|
| There are no affected 12.3 based releases |
|-------------------------------------------------------------------|
| Affected | |First Fixed Release for All |
|12.4-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|----------+---------------------------+----------------------------|
| |Releases 12.4(13d) and |Vulnerable; First fixed in |
|12.4 |prior are not vulnerable; |Release 15.0M |
| |first fixed in 12.4(25f) | |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4GC |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
|12.4JA |12.4(23c)JA4 |12.4(23c)JA4 |
| |12.4(25e)JA |12.4(25e)JA |
|----------+---------------------------+----------------------------|
|12.4JAX |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4JA |Release 12.4JA |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JDA |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JDC |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JDD |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JDE |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JHA |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JHB |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4JHC |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4JK |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4JL |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; First fixed in | |
| |Release 12.4JA |Vulnerable; First fixed in |
|12.4JX |Releases up to and |Release 12.4JA |
| |including 12.4(3g)JX2 are | |
| |not vulnerable. | |
|----------+---------------------------+----------------------------|
|12.4JY |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4JA |Release 12.4JA |
|----------+---------------------------+----------------------------|
|12.4JZ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4JA |Release 12.4JA |
|----------+---------------------------+----------------------------|
|12.4MD |12.4(22)MD3; Available on |12.4(22)MD3; Available on |
| |30-MAR-12 |30-MAR-12 |
|----------+---------------------------+----------------------------|
|12.4MDA |12.4(24)MDA11 |12.4(24)MDA11 |
|----------+---------------------------+----------------------------|
|12.4MDB |12.4(24)MDB5a |12.4(24)MDB5a |
|----------+---------------------------+----------------------------|
|12.4MDC |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| |Releases up to and |support organization per the|
|12.4MR |including 12.4(16)MR1 are |instructions in Obtaining |
| |not vulnerable. |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4MRA |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
|12.4MRB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4SW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| |12.4(15)T16 |12.4(15)T17 |
|12.4T |12.4(24)T6 |12.4(24)T7 |
| | | |
|----------+---------------------------+----------------------------|
|12.4XA |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XB |Not vulnerable |Vulnerable; First fixed in |
| | |Release 12.4T |
|----------+---------------------------+----------------------------|
|12.4XC |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XD |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XE |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XF |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XG |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XJ |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XK |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4XL |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.4XM |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4XN |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4XP |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.4XQ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XR |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 12.4T |
|----------+---------------------------+----------------------------|
|12.4XT |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|12.4XV |Not vulnerable |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
|12.4XW |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XY |Not vulnerable |Vulnerable; First fixed in |
| | |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4XZ |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+---------------------------+----------------------------|
|12.4YA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 12.4T |Release 15.0M |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4YB |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|12.4YD |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
|12.4YE |12.4(24)YE3d |12.4(24)YE3d |
|----------+---------------------------+----------------------------|
|12.4YG |12.4(24)YG4 |12.4(24)YG4 |
|----------+---------------------------+----------------------------|
| Affected | |First Fixed Release for All |
|15.0-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|----------+---------------------------+----------------------------|
|15.0M |15.0(1)M7 |15.0(1)M8 |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|15.0MR |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|15.0MRA |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
| |15.0(1)S5 |15.0(1)S5 |
|15.0S |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
| |Please see Cisco IOS XE |see Cisco IOS XE Software |
| |Software Availability |Availability |
|----------+---------------------------+----------------------------|
|15.0SA |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
| |15.0(1)SE1 | |
|15.0SE |15.0(2)SE; Available on |15.0(1)SE1 |
| |06-AUG-12 | |
|----------+---------------------------+----------------------------|
| |Not vulnerable |15.0(2)SG2 |
|15.0SG |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
| |Please see Cisco IOS-XE |see Cisco IOS-XE Software |
| |Software Availability |Availability |
|----------+---------------------------+----------------------------|
|15.0SY |Not vulnerable |15.0(1)SY1 |
|----------+---------------------------+----------------------------|
|15.0XA |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.1T |Release 15.1T |
|----------+---------------------------+----------------------------|
| |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
|15.0XO |Please see Cisco IOS-XE |see Cisco IOS-XE Software |
| |Software Availability |Availability |
|----------+---------------------------+----------------------------|
| Affected | |First Fixed Release for All |
|15.1-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|----------+---------------------------+----------------------------|
|15.1EY |15.1(2)EY1a |15.1(2)EY2 |
|----------+---------------------------+----------------------------|
|15.1GC |15.1(2)GC2 |15.1(2)GC2 |
|----------+---------------------------+----------------------------|
|15.1M |15.1(4)M2 |15.1(4)M4; Available on |
| | |30-MAR-12 |
|----------+---------------------------+----------------------------|
| | |Vulnerable; contact your |
| | |support organization per the|
|15.1MR |15.1(1)MR3 |instructions in Obtaining |
| | |Fixed Software section of |
| | |this advisory. |
|----------+---------------------------+----------------------------|
| |15.1(3)S2 |15.1(3)S2 |
|15.1S |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
| |Please see Cisco IOS XE |see Cisco IOS XE Software |
| |Software Availability |Availability |
|----------+---------------------------+----------------------------|
| |Not vulnerable |Not vulnerable |
|15.1SG |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
| |Please see Cisco IOS XE |see Cisco IOS XE Software |
| |Software Availability |Availability |
|----------+---------------------------+----------------------------|
| |Vulnerable; contact your |Vulnerable; contact your |
| |support organization per |support organization per the|
|15.1SNG |the instructions in |instructions in Obtaining |
| |Obtaining Fixed Software |Fixed Software section of |
| |section of this advisory. |this advisory. |
|----------+---------------------------+----------------------------|
|15.1SNH |Not vulnerable |Not vulnerable |
|----------+---------------------------+----------------------------|
| |15.1(1)T4 | |
|15.1T |15.1(2)T5; Available on |15.1(3)T3 |
| |27-APR-12 | |
| |15.1(3)T3 | |
|----------+---------------------------+----------------------------|
|15.1XB |Vulnerable; First fixed in |Vulnerable; First fixed in |
| |Release 15.1T |Release 15.1T |
|----------+---------------------------+----------------------------|
| Affected | |First Fixed Release for All |
|15.2-Based| First Fixed Release |Advisories in the March 2012|
| Releases | |Cisco IOS Software Security |
| | |Advisory Bundled Publication|
|----------+---------------------------+----------------------------|
|15.2GC |15.2(1)GC1 |15.2(1)GC2 |
|----------+---------------------------+----------------------------|
| |Not vulnerable |15.2(1)S1 |
| |Cisco IOS XE devices: |Cisco IOS XE devices: Please|
|15.2S |Please see Cisco IOS XE |see Cisco IOS XE Software |
| |Software Availability |Availability |
| | | |
|----------+---------------------------+----------------------------|
| |15.2(1)T2 |15.2(1)T2 |
|15.2T |15.2(2)T |15.2(2)T1 |
| |15.2(2)T1 |15.2(3)T; Available on |
| | |30-MAR-12 |
+-------------------------------------------------------------------+
* Cisco Catalyst 3550 Series Switches support the Internet Key
Exchange (IKE) feature and are vulnerable to Cisco bug ID CSCts38429
when the devices are running Layer 3 images; however, this product
reached the End of Software Maintenance milestone. Cisco 3550 Series
SMI Switches that are running Layer 2 images do not support IKE and
are not vulnerable. No other Cisco devices that run 12.2SE-based
software are vulnerable.
Cisco IOS XE Software
+--------------------
Cisco IOS XE Software is affected by the vulnerability that is
disclosed in this document.
+---------------------------------------+
| | | First Fixed |
| | | Release for |
| | | All |
| Cisco | | Advisories |
| IOS XE | First Fixed | in the March |
| Software | Release | 2012 Cisco |
| Release | | IOS Software |
| | | Security |
| | | Advisory |
| | | Bundled |
| | | Publication |
|----------+-------------+--------------|
| | | Vulnerable; |
| 2.1.x | Not | migrate to |
| | vulnerable | 3.4.2S or |
| | | later. |
|----------+-------------+--------------|
| | | Vulnerable; |
| 2.2.x | Not | migrate to |
| | vulnerable | 3.4.2S or |
| | | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 2.3.x | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 2.4.x | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 2.5.x | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 2.6.x | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 3.1.xS | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| | | Vulnerable; |
| 3.2.xSG | Not | migrate to |
| | Vulnerable | 3.2.2SG or |
| | | later. |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 3.2.xS | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| 3.2.xSG | Not | 3.2.2SG |
| | Vulnerable | |
|----------+-------------+--------------|
| | Vulnerable; | Vulnerable; |
| 3.3.xS | migrate to | migrate to |
| | 3.4.2S or | 3.4.2S or |
| | later. | later. |
|----------+-------------+--------------|
| 3.3.xSG | Not | Not |
| | Vulnerable | Vulnerable |
|----------+-------------+--------------|
| 3.4.xS | 3.4.2S | 3.4.2S |
|----------+-------------+--------------|
| 3.5.xS | Not | 3.5.1S |
| | vulnerable | |
|----------+-------------+--------------|
| 3.6.xS | Not | Not |
| | vulnerable | vulnerable |
+---------------------------------------+
For a mapping of Cisco IOS XE Software releases to Cisco IOS Software
releases, refer to Cisco IOS XE 2 Release Notes, Cisco IOS XE 3S
Release Notes, and Cisco IOS XE 3SG Release Notes.
Cisco IOS XR Software
+--------------------
Cisco IOS XR Software is not affected by any of the vulnerabilities
disclosed in the March 2012 Cisco IOS Software Security Advisory
Bundled Publication.
Workarounds
===========
If disabling the IOS SSH Server is not feasible, the following
workarounds may be useful to some customers in their environments.
SSH version 1
+------------
This vulnerability only affects SSHv2, so it can be temporarily
mitigated by applying the ip ssh version 1 global configuration
command until a software update can be completed. Customers should
be aware of the limitations and vulnerabilities of SSH version 1
protocol before applying this workaround.
vty Access Class
+---------------
It is possible to limit the exposure of the Cisco device by applying
a vty access class to allow only known, trusted hosts to connect to
the device via SSH.
For more information on restricting traffic to a vty, please consult:
http://www.cisco.com/en/US/docs/ios/12_2/ipaddr/command/reference/1rfip1.ht…
The following example permits access to the vty lines from the
192.168.1.0/24 netblock and the single IP address 172.16.1.2 while
denying access from anywhere else:
Router(config)# access-list 1 permit 192.168.1.0 0.0.0.255
Router(config)# access-list 1 permit host 172.16.1.2
Router(config)# line vty 0 4
Router(config-line)# access-class 1 in
Different Cisco platforms support a different amount of terminal
lines. Check your device's configuration to determine the correct
number of terminal lines for your platform.
Infrastructure Access Control Lists
+----------------------------------
Although it is often difficult to block traffic transiting your
network, it is possible to identify traffic that should never be
allowed to target your infrastructure devices and block that traffic
at the border of your network. Infrastructure access control lists
(iACLs) are considered a network security best practice and should be
considered as a long-term addition to good network security as well
as a workaround for this specific vulnerability. The ACL example
shown below should be included as part of the deployed infrastructure
access-list, which will protect all devices with IP addresses in the
infrastructure IP address range.
A sample access list for devices running Cisco IOS is below:
!--- Permit SSH services from trusted hosts destined
!--- to infrastructure addresses.
access-list 150 permit tcp TRUSTED_HOSTS MASK
INFRASTRUCTURE_ADDRESSES MASK eq 22
!--- Deny SSH packets from all other sources destined to
infrastructure addresses.
access-list 150 deny tcp any INFRASTRUCTURE_ADDRESSES MASK eq 22
!--- Permit all other traffic to transit the device.
access-list 150 permit IP any any
interface serial 2/0
ip access-group 150 in
The white paper titled "Protecting Your Core: Infrastructure
Protection Access Control Lists" presents guidelines and recommended
deployment techniques for infrastructure protection access lists.
This white paper is located at:
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a0…
Control Plane Policing
+---------------------
The Control Plane Policing (CoPP) feature may be used to mitigate
these vulnerabilities. In the following example, only SSH traffic
from trusted hosts with receive destination IP addresses is permitted
to reach the route processor (RP).
Note: Dropping traffic from unknown or untrusted IP addresses may
affect hosts with dynamically assigned IP addresses from connecting
to the Cisco IOS device.
access-list 152 deny tcp TRUSTED_ADDRESSES MASK any eq 22
access-list 152 permit tcp any any eq 22
!
class-map match-all COPP-KNOWN-UNDESIRABLE
match access-group 152
!
!
policy-map COPP-INPUT-POLICY
class COPP-KNOWN-UNDESIRABLE
drop
!
control-plane
service-policy input COPP-INPUT-POLICY
In the above CoPP example, the ACL entries that match the exploit
packets with the permit action result in these packets being
discarded by the policy-map drop function, while packets that match
the deny action are not affected by the policy-map drop function.
Additional information on the configuration and use of the CoPP
feature can be found at the following URL:
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6642/pr…
Obtaining Fixed Software
========================
Cisco has released free software updates that address the
vulnerability described in this advisory. Prior to deploying
software, customers are advised to consult their maintenance
providers or check the software for feature set compatibility and
known issues that are specific to their environments.
Customers may only install and expect support for feature sets they
have purchased. By installing, downloading, accessing, or otherwise
using such software upgrades, customers agree to follow the terms of
the Cisco software license at:
http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html
or as set forth at http://www.cisco.com/public/sw-center/sw-usingswc.shtml
Do not contact psirt(a)cisco.com or security-alert(a)cisco.com for
software upgrades.
Customers with Service Contracts
+-------------------------------
Customers with contracts should obtain upgraded software through
their regular update channels. For most customers, upgrades should be
obtained through the Software Center on Cisco.com at:
http://www.cisco.com
Customers Using Third-Party Support Organizations
+------------------------------------------------
Customers with Cisco products that are provided or maintained through
prior or existing agreements with third-party support organizations,
such as Cisco Partners, authorized resellers, or service providers,
should contact that organization for assistance with the appropriate
course of action.
The effectiveness of any workaround or fix depends on specific
customer situations, such as product mix, network topology, traffic
behavior, and organizational mission. Because of the variety of
affected products and releases, customers should consult their
service providers or support organizations to ensure that any applied
workaround or fix is the most appropriate in the intended network
before it is deployed.
Customers Without Service Contracts
+----------------------------------
Customers who purchase directly from Cisco but do not hold a Cisco
service contract and customers who make purchases through third-party
vendors but are unsuccessful in obtaining fixed software through
their point of sale should obtain upgrades by contacting the Cisco
Technical Assistance Center (TAC):
* +1 800 553 2447 (toll free from within North America)
* +1 408 526 7209 (toll call from anywhere in the world)
* e-mail: tac(a)cisco.com
Customers should have the product serial number available and be
prepared to provide the URL of this advisory as evidence of
entitlement to a free upgrade. Customers without service contracts
should request free upgrades through the TAC.
Refer to Cisco Worldwide Contacts at:
http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html
for additional TAC contact information, including localized telephone
numbers, instructions, and e-mail addresses for support in various languages.
Exploitation and Public Announcements
=====================================
The Cisco Product Security Incident Response Team (PSIRT) is not
aware of any public announcements or malicious use of the
vulnerability that is described in this advisory.
This vulnerability was reported to Cisco by a customer.
Status of This Notice: Final
+---------------------------
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY
KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE
INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS
AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS
DOCUMENT AT ANY TIME.
A stand-alone copy or Paraphrase of the text of this document that
omits the distribution URL in the following section is an
uncontrolled copy, and may lack important information or contain
factual errors.
Distribution
============
This advisory is posted on Cisco Security Intelligence Operations at
the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Additionally, a text version of this advisory is clear signed with
the Cisco PSIRT PGP key and circulated among the following e-mail
addresses:
* cust-security-announce(a)cisco.com
* first-bulletins(a)lists.first.org
* bugtraq(a)securityfocus.com
* vulnwatch(a)vulnwatch.org
* cisco(a)spot.colorado.edu
* cisco-nsp(a)puck.nether.net
* full-disclosure(a)lists.grok.org.uk
Future updates of this advisory, if any, will reside on Cisco.com but
may not be announced on mailing lists. Users can monitor this
advisory's URL for any updates.
Revision History
================
+---------------------------------------+
| Revision | | Initial |
| 1.0 | 2012-March-28 | public |
| | | release |
+---------------------------------------+
Cisco Security Procedures
=========================
Complete information about reporting security vulnerabilities in
Cisco products, obtaining assistance with security incidents, and
registering to receive security information from Cisco is available
on Cisco.com at:
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.…
This web page includes instructions for press inquiries regarding Cisco Security Advisories.
All Cisco Security Advisories are available at:
http://www.cisco.com/go/psirt
+--------------------------------------------------------------------
Copyright 2010-2012 Cisco Systems, Inc. All rights reserved.
+--------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
iF4EAREIAAYFAk9zNG4ACgkQQXnnBKKRMNA2VAD/eHjS4OiLcpv5x5OOjIvHSWuC
kJ7DDF+wNTvEJQWX44cA/25zYBDJKshRjHuMIzTALkM0ML4n3PNHiDMaQbphXteJ
=jhc2
-----END PGP SIGNATURE-----
1
0

Cisco Security Advisory: Cisco IOS Software Smart Install Denial of Service Vulnerability
by Cisco Systems Product Security Incident Response Team 28 Mar '12
by Cisco Systems Product Security Incident Response Team 28 Mar '12
28 Mar '12
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco Security Advisory: Cisco IOS Software Smart Install Denial of Service Vulnerability
Advisory ID: cisco-sa-20120328-smartinstall
Revision 1.0
For Public Release 2012 March 28 16:00 UTC (GMT)
+---------------------------------------------------------------------
Summary
=======
Cisco IOS Software contains a vulnerability in the Smart Install
feature that could allow an unauthenticated, remote attacker to cause
a reload of an affected device if the Smart Install feature is
enabled. The vulnerability is triggered when an affected device
processes a malformed Smart Install message on TCP port 4786.
Cisco has released free software updates that address this
vulnerability. There are no workarounds to mitigate this
vulnerability.
This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Note: The March 28, 2012, Cisco IOS Software Security Advisory
bundled publication includes nine Cisco Security Advisories. Each
advisory lists the Cisco IOS Software releases that correct the
vulnerability or vulnerabilities detailed in the advisory as well as
the Cisco IOS Software releases that correct all vulnerabilities in
the March 2012 bundled publication.
Individual publication links are in "Cisco Event Response:
Semi-Annual Cisco IOS Software Security Advisory Bundled Publication"
at the following link:
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar12.html
Affected Products
=================
Vulnerable Products
+------------------
Devices configured as a Smart Install client or director are affected
by this vulnerability. To display Smart Install information, use the
show vstack config privileged EXEC command on the Smart Install
director or client. The outputs of show commands are different when
entered on the director or on the client. The following is the output
of show vstack config in a Cisco Catalyst Switch configured as a
Smart Install client:
switch#show vstack config
Role: Client
Vstack Director IP address: 10.1.1.163
The following is the output of show vstack config in a Cisco Catalyst
Switch configured as a Smart Install director:
Director# show vstack config
Role: Director
Vstack Director IP address: 10.1.1.163
Vstack Mode: Basic
Vstack default management vlan: 1
Vstack management Vlans: none
Vstack Config file: tftp://10.1.1.100/default-config.txt
Vstack Image file: tftp://10.1.1.100/c3750e-universalk9-tar.122-
Join Window Details:
Window: Open (default)
Operation Mode: auto (default)
Vstack Backup Details:
Mode: On (default)
Repository: flash:/vstack (default)
The Smart Install Feature is enabled by default.
To determine the Cisco IOS Software release that is running on a
Cisco product, administrators can log in to the device and issue the
show version command to display the system banner. The system banner
confirms that the device is running Cisco IOS Software by displaying
text similar to "Cisco Internetwork Operating System Software" or
"Cisco IOS Software." The image name displays in parentheses,
followed by "Version" and the Cisco IOS Software release name. Other
Cisco devices do not have the show version command or may provide
different output.
The following example identifies a Cisco product that is running
Cisco IOS Software Release 15.0(1)M1 with an installed image name of
C3900-UNIVERSALK9-M:
Router> show version
Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.0(1)M1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 02-Dec-09 17:17 by prod_rel_team
!--- output truncated
Additional information about Cisco IOS Software release naming
conventions is available in "White Paper: Cisco IOS and NX-OS
Software Reference Guide" at:
http://www.cisco.com/web/about/security/intelligence/ios-ref.html
Products Confirmed Not Vulnerable
+--------------------------------
Cisco IOS XR Software is not affected by this vulnerability.
Cisco IOS XE Software is not affected by this vulnerability.
No other Cisco products are currently known to be affected by this
vulnerability.
Details
=======
Smart Install is a plug-and-play configuration and image-management
feature that provides zero-touch deployment for new LAN Ethernet
switches. This feature allows, for example, new LAN switches to be
deployed at new locations without any configuration.
A vulnerability exists in the Smart Install feature of Cisco IOS
Software that could allow an unauthenticated, remote attacker to
cause a reload of an affected device. Smart Install uses a Cisco
proprietary protocol that runs over TCP port 4786. To exploit this
vulnerability, an attacker needs to establish a TCP session on port
4786 of an affected device that has the Smart Install feature
enabled, and then send a malformed Smart Install message.
This vulnerability is documented in Cisco bug ID CSCtt16051
and has been assigned Common Vulnerabilities and Exposures (CVE)
ID CVE-2012-0385.
Vulnerability Scoring Details
=============================
Cisco has scored the vulnerability in this advisory based on the
Common Vulnerability Scoring System (CVSS). The CVSS scoring in this
security advisory is in accordance with CVSS version 2.0.
CVSS is a standards-based scoring method that conveys vulnerability
severity and helps organizations determine the urgency and priority
of a response.
Cisco has provided a base and temporal score. Customers can also
compute environmental scores that help determine the impact of the
vulnerability in their own networks.
Cisco has provided additional information regarding CVSS at the
following link:
http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html
Cisco has also provided a CVSS calculator to compute the
environmental impact for individual networks at the following link:
http://intellishield.cisco.com/security/alertmanager/cvss
* Cisco IOS Software Smart Install Denial of Service Vulnerability
CVSS Base Score - 7.8
Access Vector - Network
Access Complexity - Low
Authentication - None
Confidentiality Impact - None
Integrity Impact - None
Availability Impact - Complete
CVSS Temporal Score - 6.4
Exploitability - Functional
Remediation Level - Official-Fix
Report Confidence - Confirmed
Impact
======
Successful exploitation of the vulnerability that is described in
this advisory may cause a reload of an affected device. Repeated
exploitation could result in a sustained denial of service condition.
Software Versions and Fixes
===========================
When considering software upgrades, also consult:
http://www.cisco.com/go/psirt and any subsequent advisories
to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the
devices to be upgraded contain sufficient memory and that current
hardware and software configurations will continue to be supported
properly by the new release. If the information is not clear, contact
the Cisco Technical Assistance Center (TAC) or your contracted
maintenance provider for assistance.
Cisco IOS Software
+-----------------
Each row of the following Cisco IOS Software table corresponds to a
Cisco IOS Software train. If a particular train is vulnerable, the
earliest releases that contain the fix are listed in the First Fixed
Release column. The First Fixed Release for All Advisories in the
March 2012 Bundled Publication column lists the earliest possible
releases that correct all the published vulnerabilities in the Cisco
IOS Software Security Advisory bundled publication. Cisco recommends
upgrading to the latest available release, where possible.
The Cisco IOS Software Checker allows customers to search for Cisco
Security Advisories that address specific Cisco IOS Software
releases. This tool is available on the Cisco Security Intelligence
Operations (SIO) portal at:
http://tools.cisco.com/security/center/selectIOSVersion.x
+-------------------------------------------------------------------+
| Major | Availability of Repaired Releases |
| Release | |
|----------+--------------------------------------------------------|
| Affected | | First Fixed Release for All |
|12.0-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|-------------------------------------------------------------------|
| There are no affected 12.0 based releases |
|-------------------------------------------------------------------|
| Affected | | First Fixed Release for All |
|12.2-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|----------+---------------------+----------------------------------|
|12.2 |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2B |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2BC |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2BW |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2BX |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SB |
|----------+---------------------+----------------------------------|
|12.2BY |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2BZ |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2CX |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2CY |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2CZ |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.0S |
|----------+---------------------+----------------------------------|
|12.2DA |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2DD |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2DX |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2EU |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2EW |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2EWA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| |Vulnerable; First | |
| |fixed in Release | |
|12.2EX |15.0SE |Vulnerable; First fixed in Release|
| |Releases up to and |15.0SE |
| |including 12.2(46)EX | |
| |are not vulnerable. | |
|----------+---------------------+----------------------------------|
| |Vulnerable; migrate | |
| |to any release in | |
|12.2EY |15.1EY |12.2(52)EY4 |
| |Releases up to and | |
| |including 12.2(52)EY4| |
| |are not vulnerable. | |
|----------+---------------------+----------------------------------|
| |Vulnerable; First | |
| |fixed in Release | |
|12.2EZ |15.0SE |Vulnerable; First fixed in Release|
| |Releases up to and |15.0SE |
| |including 12.2(53)EZ | |
| |are not vulnerable. | |
|----------+---------------------+----------------------------------|
|12.2FX |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2FY |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2FZ |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2IRA |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2IRB |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2IRC |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2IRD |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2IRE |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2IRF |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IRG |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IRH |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXB |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXC |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXD |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXE |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXF |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXG |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2IXH |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2JA |Not vulnerable |Not vulnerable |
|----------+---------------------+----------------------------------|
|12.2JK |Not vulnerable |Not vulnerable |
|----------+---------------------+----------------------------------|
|12.2MB |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2MC |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2MRA |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2MRB |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Releases prior to 12.2(30)S are |
|12.2S |Not vulnerable |vulnerable; Releases 12.2(30)S and|
| | |later are not vulnerable. First |
| | |fixed in Release 12.0S |
|----------+---------------------+----------------------------------|
|12.2SB |Not vulnerable |12.2(33)SB12 |
|----------+---------------------+----------------------------------|
|12.2SBC |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2SCA |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SCE |
|----------+---------------------+----------------------------------|
|12.2SCB |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SCE |
|----------+---------------------+----------------------------------|
|12.2SCC |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SCE |
|----------+---------------------+----------------------------------|
|12.2SCD |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SCE |
|----------+---------------------+----------------------------------|
|12.2SCE |Not vulnerable |12.2(33)SCE6 |
|----------+---------------------+----------------------------------|
|12.2SCF |Not vulnerable |12.2(33)SCF2 |
|----------+---------------------+----------------------------------|
|12.2SE |12.2(55)SE5 | |
| | |12.2(55)SE5 * |
|----------+---------------------+----------------------------------|
|12.2SEA |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SEB |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SEC |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SED |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SEE |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SEF |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SEG |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0SE |
|----------+---------------------+----------------------------------|
|12.2SG |Not vulnerable |12.2(53)SG7; Available on |
| | |07-MAY-12 |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SGA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2SL |Not vulnerable |Not vulnerable |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SM |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SO |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SQ |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2SRA |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2SRB |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2SRC |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2SRD |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
|12.2SRE |Not vulnerable |12.2(33)SRE6 |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2STE |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2SU |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2SV |Not vulnerable |Releases up to and including 12.2 |
| | |(18)SV2 are not vulnerable. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SVA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SVC |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SVD |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SVE |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2SW |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.4T |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SX |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXB |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXD |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXE |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXF |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2SXH |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2SXI |Not vulnerable |12.2(33)SXI9 |
|----------+---------------------+----------------------------------|
|12.2SXJ |Not vulnerable |12.2(33)SXJ2 |
|----------+---------------------+----------------------------------|
|12.2SY |Not vulnerable |12.2(50)SY2; Available on |
| | |11-JUN-12 |
|----------+---------------------+----------------------------------|
|12.2SZ |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.0S |
|----------+---------------------+----------------------------------|
|12.2T |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2TPC |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2XA |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XB |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XC |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XD |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XE |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XF |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XG |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XH |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XI |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XJ |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XK |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XL |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XM |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XNA |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XNB |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XNC |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XND |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XNE |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| |Please see Cisco |Please see Cisco IOS-XE Software |
|12.2XNF |IOS-XE Software |Availability |
| |Availability | |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2XO |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2XQ |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| | |Releases prior to 12.2(15)XR are |
|12.2XR |Not vulnerable |vulnerable; Releases 12.2(15)XR |
| | |and later are not vulnerable. |
| | |First fixed in Release 15.0M |
|----------+---------------------+----------------------------------|
|12.2XS |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XT |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XU |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XV |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2XW |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2YA |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YC |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YD |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YE |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YK |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YO |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; First fixed in Release|
|12.2YP |Not vulnerable |15.0M |
| | |Releases up to and including 12.2 |
| | |(8)YP are not vulnerable. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YT |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YW |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YX |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YY |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2YZ |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZB |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZC |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZD |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2ZE |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
|12.2ZH |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.0M |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZJ |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZP |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZU |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|12.2ZX |Not vulnerable |Vulnerable; First fixed in Release|
| | |12.2SRE |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZY |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|12.2ZYA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| Affected | | First Fixed Release for All |
|12.3-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|-------------------------------------------------------------------|
| There are no affected 12.3 based releases |
|-------------------------------------------------------------------|
| Affected | | First Fixed Release for All |
|12.4-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|-------------------------------------------------------------------|
| There are no affected 12.4 based releases |
|-------------------------------------------------------------------|
| Affected | | First Fixed Release for All |
|15.0-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|----------+---------------------+----------------------------------|
|15.0M |Not vulnerable |15.0(1)M8 |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|15.0MR |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|15.0MRA |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| |Not vulnerable | |
| |Cisco IOS XE devices:|15.0(1)S5 |
|15.0S |Please see Cisco IOS |Cisco IOS XE devices: Please see |
| |XE Software |Cisco IOS XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
|15.0SA |Not vulnerable |Not vulnerable |
|----------+---------------------+----------------------------------|
|15.0SE |15.0(1)SE1 |15.0(1)SE1 |
|----------+---------------------+----------------------------------|
| |Not vulnerable | |
| |Cisco IOS XE devices:|15.0(2)SG2 |
|15.0SG |Please see Cisco IOS |Cisco IOS XE devices: Please see |
| |XE Software |Cisco IOS XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
|15.0SY |Not vulnerable |15.0(1)SY1 |
|----------+---------------------+----------------------------------|
|15.0XA |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.1T |
|----------+---------------------+----------------------------------|
| |Cisco IOS XE devices:| |
|15.0XO |Please see Cisco |Cisco IOS XE devices: Please see |
| |IOS-XE Software |Cisco IOS-XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
| Affected | | First Fixed Release for All |
|15.1-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|----------+---------------------+----------------------------------|
|15.1EY |Not vulnerable |15.1(2)EY2 |
|----------+---------------------+----------------------------------|
|15.1GC |Not vulnerable |15.1(2)GC2 |
|----------+---------------------+----------------------------------|
|15.1M |15.1(4)M4; Available |15.1(4)M4; Available on 30-MAR-12 |
| |on 30-MAR-12 | |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|15.1MR |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
| |Not vulnerable | |
| |Cisco IOS XE devices:|15.1(3)S2 |
|15.1S |Please see Cisco IOS |Cisco IOS XE devices: Please see |
| |XE Software |Cisco IOS XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
| |Not vulnerable | |
| |Cisco IOS XE devices:|Not vulnerable |
|15.1SG |Please see Cisco IOS |Cisco IOS XE devices: Please see |
| |XE Software |Cisco IOS XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
| | |Vulnerable; contact your support |
|15.1SNG |Not vulnerable |organization per the instructions |
| | |in Obtaining Fixed Software |
| | |section of this advisory. |
|----------+---------------------+----------------------------------|
|15.1SNH |Not vulnerable |Not vulnerable |
|----------+---------------------+----------------------------------|
|15.1T |15.1(3)T3 |15.1(3)T3 |
|----------+---------------------+----------------------------------|
|15.1XB |Not vulnerable |Vulnerable; First fixed in Release|
| | |15.1T |
|----------+---------------------+----------------------------------|
| Affected | | First Fixed Release for All |
|15.2-Based| First Fixed Release |Advisories in the March 2012 Cisco|
| Releases | | IOS Software Security Advisory |
| | | Bundled Publication |
|----------+---------------------+----------------------------------|
|15.2GC |15.2(1)GC2 |15.2(1)GC2 |
|----------+---------------------+----------------------------------|
| |Not vulnerable |15.2(1)S1 |
| |Cisco IOS XE devices:| |
|15.2S |Please see Cisco IOS |Cisco IOS XE devices: Please see |
| |XE Software |Cisco IOS XE Software Availability|
| |Availability | |
|----------+---------------------+----------------------------------|
| |15.2(1)T2 |15.2(1)T2 |
|15.2T |15.2(2)T1 |15.2(2)T1 |
| |15.2(3)T; Available |15.2(3)T; Available on 30-MAR-12 |
| |on 30-MAR-12 | |
+-------------------------------------------------------------------+
* Cisco Catalyst 3550 Series Switches support the Internet Key
Exchange (IKE) feature and are vulnerable to Cisco bug ID CSCts38429
when the devices are running Layer 3 images; however, this product
reached the End of Software Maintenance milestone. Cisco 3550 Series
SMI Switches that are running Layer 2 images do not support IKE and
are not vulnerable. No other Cisco devices that run 12.2SE-based
software are vulnerable.
Cisco IOS XE Software
+--------------------
Cisco IOS XE Software is not affected by the vulnerability disclosed
in this advisory.
Cisco IOS XR Software
+--------------------
Cisco IOS XR Software is not affected by any of the vulnerabilities
disclosed in the March 2012 Cisco IOS Software Security Advisory
Bundled Publication.
Workarounds
===========
There are no workarounds available to mitigate this vulnerability
other than disabling the Smart Install feature. To disable the Smart
Install feature use the global configuration command no vstack.
Additional mitigations that can be deployed on Cisco devices within
the network are available in the Cisco Applied Mitigation Bulletin
companion document for this advisory, which is available at the
following link:
http://tools.cisco.com/security/center/content/CiscoAppliedMitigationBullet…
Obtaining Fixed Software
========================
Cisco has released free software updates that address the
vulnerability described in this advisory. Prior to deploying
software, customers are advised to consult their maintenance
providers or check the software for feature set compatibility and
known issues that are specific to their environments.
Customers may only install and expect support for feature sets they
have purchased. By installing, downloading, accessing, or otherwise
using such software upgrades, customers agree to follow the terms of
the Cisco software license at:
http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html
or as set forth at http://www.cisco.com/public/sw-center/sw-usingswc.shtml
Do not contact psirt(a)cisco.com or security-alert(a)cisco.com for
software upgrades.
Customers with Service Contracts
+-------------------------------
Customers with contracts should obtain upgraded software through
their regular update channels. For most customers, upgrades should be
obtained through the Software Center on Cisco.com at:
http://www.cisco.com
Customers Using Third-Party Support Organizations
+------------------------------------------------
Customers with Cisco products that are provided or maintained through
prior or existing agreements with third-party support organizations,
such as Cisco Partners, authorized resellers, or service providers,
should contact that organization for assistance with the appropriate
course of action.
The effectiveness of any workaround or fix depends on specific
customer situations, such as product mix, network topology, traffic
behavior, and organizational mission. Because of the variety of
affected products and releases, customers should consult their
service providers or support organizations to ensure that any applied
workaround or fix is the most appropriate in the intended network
before it is deployed.
Customers Without Service Contracts
+----------------------------------
Customers who purchase directly from Cisco but do not hold a Cisco
service contract and customers who make purchases through third-party
vendors but are unsuccessful in obtaining fixed software through
their point of sale should obtain upgrades by contacting the Cisco
Technical Assistance Center (TAC):
* +1 800 553 2447 (toll free from within North America)
* +1 408 526 7209 (toll call from anywhere in the world)
* e-mail: tac(a)cisco.com
Customers should have the product serial number available and be
prepared to provide the URL of this advisory as evidence of
entitlement to a free upgrade. Customers without service contracts
should request free upgrades through the TAC.
Refer to Cisco Worldwide Contacts at:
http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html
for additional TAC contact information, including localized telephone
numbers, instructions, and e-mail addresses for support in various languages.
Exploitation and Public Announcements
=====================================
The Cisco Product Security Incident Response Team (PSIRT) is not
aware of any public announcements or malicious use of the
vulnerability that is described in this advisory.
This issue was reported to Cisco by customers who discovered it
during the course of security audits.
Status of This Notice: Final
+---------------------------
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY
KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE
INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS
AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS
DOCUMENT AT ANY TIME.
A stand-alone copy or Paraphrase of the text of this document that
omits the distribution URL in the following section is an
uncontrolled copy, and may lack important information or contain
factual errors.
Distribution
============
This advisory is posted on Cisco Security Intelligence Operations at
the following link
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-…
Additionally, a text version of this advisory is clear signed with
the Cisco PSIRT PGP key and circulated among the following e-mail
addresses:
* cust-security-announce(a)cisco.com
* first-bulletins(a)lists.first.org
* bugtraq(a)securityfocus.com
* vulnwatch(a)vulnwatch.org
* cisco(a)spot.colorado.edu
* cisco-nsp(a)puck.nether.net
* full-disclosure(a)lists.grok.org.uk
Future updates of this advisory, if any, will reside on Cisco.com but
may not be announced on mailing lists. Users can monitor this
advisory's URL for any updates.
Revision History
================
+---------------------------------------+
| Revision | | Initial |
| 1.0 | 2012-March-28 | public |
| | | release. |
+---------------------------------------+
Cisco Security Procedures
=========================
Complete information about reporting security vulnerabilities in
Cisco products, obtaining assistance with security incidents, and
registering to receive security information from Cisco is available
on Cisco.com at:
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.…
This web page includes instructions for press inquiries regarding
Cisco Security Advisories.
All Cisco Security Advisories are available at:
http://www.cisco.com/go/psirt
+--------------------------------------------------------------------
Copyright 2010-2012 Cisco Systems, Inc. All rights reserved.
+--------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (SunOS)
iFcDBQFPcSThQXnnBKKRMNARCOH4AP9Wgc8t/hVLf4NZrWSE6Y64edlgu+lg7MB6
h5OtNEQTgAD/Ux8fxWyhS8HGYK17bT294K2OMuymiytT5sN/T2u/ZY8=
=6eFE
-----END PGP SIGNATURE-----
1
0
> Brant Ian Stevens <mailto:branto@argentiumsolutions.com>
> March 28, 2012 11:41 AM
> The CER is the perfect box for this application, save for the
> redundant processors. The MLXe will work great if you want a small
> form factor and redundant processors.
>
> -Brant
> George Bonser <mailto:gbonser@seven.com>
> March 28, 2012 11:34 AM
>
>
> I have been using a pair of CER (but not the -RT) at one location for
> a while now and so far have been flawless. These particular units
> aren't taking full tables so don't need the -RT but I wouldn't have
> any trouble using them. The -RT are basically a 1U XMR.
>
> Tom Daly <mailto:tom@dyn.com>
> March 27, 2012 11:59 PM
> Brent,
> Your options include, for smaller boxes:
>
> - Brocade CER series, but make sure you the -RT versions due to RAM
> (haven't tried, though)
> - Juniper MX (MX80 is working well for us)
> - Cisco ASR1006 (heard a lot about BGP price issues)
>
> But for 300mb/sec, what not OpenBSD + Quagga?
>
> Tom
>
>
>
> ----- Original Message -----
>
> Jo Rhett <mailto:jrhett@netconsonance.com>
> March 27, 2012 6:00 PM
> I was very happy with the E300 as a data center core switch handling
> multiple full feeds (around 15) with about 10x the traffic you are
> talking about. The only problem I had was that Force10 didn't have a
> useful (basically forklift) upgrade to get more IPv4 prefixes, and the
> more I talked to them and the more I showed them the graphs
> demonstrating what we'd need for prefix space assuming even the most
> conservative assumptions at depletion, the more I realized they really
> Did Not Get It. In fact, their brand new architecture recently
> announced had only 500k prefixes allowed, at a time that the Juniper
> MX platform handled 2million easily.
>
> So I would be fine using Force10 again, given the following changes:
> 1. Large limits on IP prefixes allowed
> 2. Reallocation of useless memory from stupid things like MAC tables
> to prefixes (data centers have very few MACs, very many prefixes)
> 3. Command line logging
>
> The units worked great at failover, never had any problems gracefully
> failing over from one RP to another, but if you have to cold boot them
> for any reason it takes like 5 minutes :(
>
1
0
Hello all,
I was wondering when can we actually expect RPKI / origin validation
support from router vendors. I know where Cisco and Juniper stand, in
fact, I have been testing both implementations.
So, I would like to know if some one has heard anything from:
- Huawei
- Alcatel
- Others ?
regards
Carlos
1
0
Rrlr
----- Original Message -----
From: nanog-request(a)nanog.org <nanog-request(a)nanog.org>
To: nanog(a)nanog.org <nanog(a)nanog.org>
Sent: Tue Mar 27 11:22:36 2012
Subject: NANOG Digest, Vol 50, Issue 113
Send NANOG mailing list submissions to
nanog(a)nanog.org
To subscribe or unsubscribe via the World Wide Web, visit
https://mailman.nanog.org/mailman/listinfo/nanog
or, via email, send a message with subject or body 'help' to
nanog-request(a)nanog.org
You can reach the person managing the list at
nanog-owner(a)nanog.org
When replying, please edit your Subject line so it is more specific
than "Re: Contents of NANOG digest..."
Today's Topics:
1. Re: OWA blocked by China (TR Shaw)
2. RE: OWA blocked by China (Thomas York)
3. Re: Muni Fiber (Ray Soucy)
4. Re: Muni Fiber (was: Re: last mile, regulatory incentives,
etc) (Owen DeLong)
5. Re: Muni Fiber (Owen DeLong)
----------------------------------------------------------------------
Message: 1
Date: Tue, 27 Mar 2012 10:45:25 -0400
From: TR Shaw <tshaw(a)oitc.com>
To: Jim Gonzalez <jim(a)impactbusiness.com>
Cc: nanog(a)nanog.org
Subject: Re: OWA blocked by China
Message-ID: <DD584E3F-7B92-4076-8983-A24C8D699E6D(a)oitc.com>
Content-Type: text/plain; charset=us-ascii
On Mar 27, 2012, at 10:16 AM, Jim Gonzalez wrote:
> Hello,
>
> One of my customers has workers in China. There outlook web
> access is blocked by the China Firewall. I was just wondering if anyone had
> this issue ? I have not tried any work arounds as of yet just gathering info
>
Jim
Try a tunnel?
Tom
------------------------------
Message: 2
Date: Tue, 27 Mar 2012 10:50:53 -0400
From: "Thomas York" <straterra(a)fuhell.com>
To: <tshaw(a)oitc.com>, <jim(a)impactbusiness.com>
Cc: nanog(a)nanog.org
Subject: RE: OWA blocked by China
Message-ID: <008501cd0c29$0383bc90$0a8b35b0$(a)fuhell.com>
Content-Type: text/plain; charset="us-ascii"
Good luck with that. I have three plants in China and China Telecom loves
batting down our VPN tunnels. They've left the current solution alone for a
few months now. It appears they try to do DPI on SSL/IPSec to see if it's a
VPN tunnel. I placed our SSL OpenVPN tunnel inside of a GRE tunnel. For some
reason, they don't seem to be doing DPI on it and mostly leave it alone now.
I'm sure it'll change at some point soon, though.
-- Thomas York
-----Original Message-----
From: TR Shaw [mailto:tshaw@oitc.com]
Sent: Tuesday, March 27, 2012 10:45 AM
To: Jim Gonzalez
Cc: nanog(a)nanog.org
Subject: Re: OWA blocked by China
On Mar 27, 2012, at 10:16 AM, Jim Gonzalez wrote:
> Hello,
>
> One of my customers has workers in China. There outlook
> web access is blocked by the China Firewall. I was just wondering if
> anyone had this issue ? I have not tried any work arounds as of yet
> just gathering info
>
Jim
Try a tunnel?
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 7138 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20120327/c6d00a21/atta…>
------------------------------
Message: 3
Date: Tue, 27 Mar 2012 10:57:51 -0400
From: Ray Soucy <rps(a)maine.edu>
To: Miles Fidelman <mfidelman(a)meetinghouse.net>
Cc: NANOG <nanog(a)nanog.org>
Subject: Re: Muni Fiber
Message-ID:
<CALFTrnMbqbqUxd4RJZN6jtBWOo94LQfg-3xy6qp8LBk7_kn+oQ(a)mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1
"Politically and legally are another matter" being key ;-)
It was a long hard fight even in Maine to get a dark fiber utility (over a
year of going before the legislature). The ILEC lobbyists are very
influential and want to maintain the status quo at all costs.
A lot of the examples you listed are pilot projects that providers do
mostly for PR purposes so they can say "we provide FTTH" with a "* in
select areas" footnote. They rarely see any large scale adoption and are
usually operated at a loss.
I think the key problem is that building out fiber doesn't make business
sense if each provider in an area has to build out identical infrastructure
and doesn't have the safety of a monopoly. As mentioned, providers are
also concerned with the time it will take to realize ROI. The result is
that we need to subsidize this infrastructure if we want it, but we end up
with no competition and poor service if the service provider is the one
getting those subsidies. Aside from very urban areas where the density can
support the investment, the only solution becomes to create an open access
public utility to maintain the fiber plant, cans, huts, etc. and prohibit
them from offering any lit services over that fiber.
As for rural areas not needing broadband; I think it's a matter of
national interest that everyone has access to broadband. Just like power.
When we make an effort to lift everyone up, we all do better.
The Internet, like the Interstate highway system, is a time machine. It
shortens distances between people and makes us more productive. Even
better, it allows businesses to locate anywhere.
On Tue, Mar 27, 2012 at 10:02 AM, Miles Fidelman <mfidelman(a)meetinghouse.net
> wrote:
> Ray Soucy wrote:
>
>>
>> If people got serious about FTTH, I think a _very_ optimistic timeline
>> would be something like:
>>
>
> Not optimistic at all, technically or operationally. Politically and
> legally are another matter:
>
>>
>> 2015 - First communities coming online, 100M to the home (probably Gigabit
>> line rate, but throttled).
>>
>
> There's been quite a lot of FTTH for quite a few years now. In addition
> to the Verizon FIOS stuff - up to 135mbps down/ 35mbps up available where I
> am (though I've been quite happy with lower speeds).
>
> Municipal electric utilities have been deploying fiber right and left.
> Probably 200 systems operational. The two that come to mind immediately
> are:
>
> Chattanooga, TN - GigE FTTH Today - http://chattanoogagig.com/ -
>
> Grant County PUD (public utility district), OR has had the fiber in for a
> few years, selling wholesale - not sure what specific retail services are
> available
>
> There'd probably be a lot more available if the big telcos and cable
> companies weren't doing everything they can to block municipal bids.
>
>
>
>
>
>
> --
> In theory, there is no difference between theory and practice.
> In practice, there is. .... Yogi Berra
>
>
>
>
--
Ray Soucy
Epic Communications Specialist
Phone: +1 (207) 561-3526
Networkmaine, a Unit of the University of Maine System
http://www.networkmaine.net/
------------------------------
Message: 4
Date: Tue, 27 Mar 2012 08:03:44 -0700
From: Owen DeLong <owen(a)delong.com>
To: Jay Ashworth <jra(a)baylink.com>
Cc: NANOG <nanog(a)nanog.org>
Subject: Re: Muni Fiber (was: Re: last mile, regulatory incentives,
etc)
Message-ID: <AF7AB7CD-AB81-4D99-82DD-37688FFB18E1(a)delong.com>
Content-Type: text/plain; charset=us-ascii
Actual public financed non-muni fiber is skipping the easy parts and deploying only a few of the hard parts.
(current actual results of USF)
How is that an improvement?
Owen
On Mar 25, 2012, at 8:47 AM, Jay Ashworth wrote:
> Well, for my part, /most of the poiny/ of muni is The Public Good; if /actual/ bond financed muni fiber is skipping the Hard Parts, it deserves to lose.
>
> Time to assemble some stats, I guess.
> -- jra
> --
> Sent from my Android phone with K-9 Mail. Please excuse my brevity.
>
> Owen DeLong <owen(a)delong.com> wrote:
> Who cares?
>
> It's time to stop letting rural deployments stand in the way of municipal deployments.
>
> It's a natural part of living outside of a population center that it costs more to bring utility services to you. I'm not entirely opposed (though somewhat) to subsidizing that to some extent, but, I'm tired of municipal deployments being blocked by this sense of equal entitlement to rural.
>
> The rural builds cost more, take longer, and yield lower revenues. It makes no sense to let that stand in the way of building out municipalities. Nothing prevents rural residents who have the means and really want their buildout prioritized from building a collective to get it done.
>
> Subsidizing rural build-out is one thing. Failing to build out municipalities because of some sense of rural entitlement? That's just stupid.
>
> Owen
>
>
> Sent from my iPa
> d
>
> On Mar 24, 2012, at 12:42 PM, "Frank Bulk" <frnkblk(a)iname.com> wrote:
>
> > How many munis serve the rural like they do the urban?
> >
> > In the vast majority of cases the munis end up doing what ILECs only wish they could do -- serve the most profitable customers.
> >
> > Frank
> >
> > -----Original Message-----
> > From: Jay Ashworth [mailto:jra@baylink.com]
> > Sent: Thursday, March 22, 2012 12:52 PM
> > To: NANOG
> > Subject: Muni Fiber (was: Re: last mile, regulatory incentives, etc)
> >
> > <snip>
> >
> > Oh, it's *much* worse than that, John.
> >
> > The *right*, long term solution to all of these problems is for
> > municipalities to do the fiber build, properly engineered, and even
> > subbed out to a contractor to build and possibly operate...
> >
> > offering *only* layer 1 service at wholesale. Any comer
> can
> light up
> > each city's pop, and offer retail service over the FTTH fiber to that
> > customer at whatever rate they like, and the city itself doesn't offer
> > layer 2 or 3 service at all.
> >
> > High-speed optical data *is* the next natural monopoly, after power
> > and water/sewer delivery, and it's time to just get over it and do it
> > right.
> >
> > As you might imagine, this environment -- one where the LEC doesn't own
> > the physical plant -- scares the ever-lovin' daylights out of Verizon
> > (among others), so much so that they *have gotten it made illegal* in
> > several states, and they're lobbying to expand that footprint.
> >
> > See, among other sites: http://www.muninetworks.org/
> >
> > As you might imagine, I am a fairly strong proponent of muni layer 1 --
> > or even layer 2, where the municipality suppli
> es
> (matching) ONTs, and
> > services have to fit over GigE -- fiber delivery of high-speed data
> > service.
> >
> > I believe Google agrees with me. :-)
> >
> > Cheers,
> > -- jra
> >
> > Cheers,
> > -- jra
> > --
> > Jay R. Ashworth Baylink jra(a)baylink.com
> > Designer The Things I Think RFC 2100
> > Ashworth & Associates http://baylink.pitas.com 2000 Land Rover DII
> > St Petersburg FL USA http://photo.imageinc.us +1 727 647 1274
> >
> >
> >
------------------------------
Message: 5
Date: Tue, 27 Mar 2012 08:19:46 -0700
From: Owen DeLong <owen(a)delong.com>
To: Leo Bicknell <bicknell(a)ufp.org>
Cc: nanog(a)nanog.org
Subject: Re: Muni Fiber
Message-ID: <72636209-A7EF-4AB8-A145-55D6B3A06EAD(a)delong.com>
Content-Type: text/plain; charset=us-ascii
>
> Politically the makings of a similar situation already exist.
> Goverment has swung the USF funds to fuel rual broadband, strongly
> favoring FTTx where it makes sense. While companies like Verizon
> enjoy not having to share their fiber lines now, these same forces
> will conspire to drive unbundling in fiber, just as it did in copper.
> What they are getting now is simply a first mover advantage.
>
It's a bigger first mover advantage. They've learned their lesson from the
copper unbundling and they are being allowed to deploy fiber in ways
that will make it hard (impossible) to sell it on an unbundled basis later.
> Government at the end of the day will fund the 20-40% of America
> which is profitable in the long run, but not in commercial time
> scales. They will also fund the 10% of America which will never
> be profitable, no mater what. It happened with Electricity and
> Telephone, and I suspect the societal drivers to do the same with
> the Internet will be even stronger. Companies will have to accept an
> unbundled tail to get access to this 30-50% of the market; and while
> they aren't interested now, they will be very soon.
Maybe, but, if what is happening now is allowed to continue, it will:
1. Not encourage competition anywhere.
2. Allow existing monopolies to preserve and extend those monopolies.
3. Cost even more than it already has.
4. Continue to lag behind the rest of the world.
5. Result in an inferior solution.
What is needed is for regulators to step up with a bold vision for the
public good. We need to encourage (or even require) local authorities
to deploy (themselves or by contract) independent L1 infrastructure (yes,
I like the 4-8 strands per residence star topology idea) to every structure
within their jurisdiction and make it available to L2+ service providers
on an equal-cost-per-subscriber basis in each jurisdiction.
Yes, this means that the cost per subscriber will be lower in denser
jurisdictions than it will be in less dense jurisdictions. However, users
in those jurisdictions should expect to pay more for services and the
ability to attract L2+ service providers can be achieved in a variety
of ways.
The important thing is to make sure that if public money is being used
to build infrastructure, it becomes infrastructure that is useful to said
public and not just a subsidy to some corporation for extending its
monopoly in a manner that is often contrary to the public good.
Unfortunately, that is exactly where the money is going today.
Owen
End of NANOG Digest, Vol 50, Issue 113
**************************************
This E-mail and any of its attachments may contain Time Warner Cable proprietary information, which is privileged, confidential, or subject to copyright belonging to Time Warner Cable. This E-mail is intended solely for the use of the individual or entity to which it is addressed. If you are not the intended recipient of this E-mail, you are hereby notified that any dissemination, distribution, copying, or action taken in relation to the contents of and attachments to this E-mail is strictly prohibited and may be unlawful. If you have received this E-mail in error, please notify the sender immediately and permanently delete the original and any copy of this E-mail and any printout.
1
0
Hello,
One of my customers has workers in China. There outlook web
access is blocked by the China Firewall. I was just wondering if anyone had
this issue ? I have not tried any work arounds as of yet just gathering info
Thanks in advance
Jim Gonzalez
5
5
http://www.extremetech.com/extreme/122989-1-5-billion-the-cost-of-cutting-l…
$1.5 billion: The cost of cutting London-Tokyo latency by 60ms
By Sebastian Anthony on March 20, 2012 at 1:04 pm
Arctic Link submarine cable
Starting this summer, a convoy of ice breakers and specially-adapted polar
ice-rated cable laying ships will begin to lay the first ever trans-Arctic
Ocean submarine fiber optic cables. Two of these cables, called Artic Fibre
and Arctic Link, will cross the Northwest Passage which runs through the
Canadian Arctic Archipelago. A third cable, the Russian Optical Trans-Arctic
Submarine Cable System (ROTACS), will skirt the north coast of Scandinavia
and Russia. All three cables will connect the United Kingdom to Japan, with a
smattering of branches that will provide high-speed internet access to a
handful of Arctic Circle communities. The completed cables are estimated to
cost between $600 million and $1.5 billion each.
All three cables are being laid for the same reasons: Redundancy and speed.
As it stands, it takes roughly 230 milliseconds for a packet to go from
London to Tokyo; the new cables will reduce this by 30% to 170ms. This
speed-up will be gained by virtue of a much shorter run: Currently, packets
from the UK to Japan either have to traverse Europe, the Middle East, and the
Indian Ocean, or the Atlantic, US, and Pacific, both routes racking up around
15,000 miles in the process. It’s only 10,000 miles (16,000km) across the
Arctic Ocean, and you don’t have to mess around with any land crossings,
either.
Russian Optical Trans-Arctic Submarine Cable System (ROTACS) between UK and
JapanThe massive drop in latency is expected to supercharge algorithmic stock
market trading, where a difference of a few milliseconds can gain (or lose)
millions of dollars. It is for this reason that a new cable is currently
being laid between the UK and US — it will cost $300 million and shave “just”
six milliseconds off the fastest link currently available. The lower latency
will also be a boon to other technologies that hinge heavily on the internet,
such as telemedicine (and teleconferencing) and education. Telephone calls
and live news coverage would also enjoy the significantly lower latency. Each
of the fiber optic cables will have a capacity in the terabits-per-second
range, which will probably come in handy too.
Beyond the stock markets, though, the main advantage of the three new cables
is added redundancy. Currently, almost every cable that lands in Asia goes
through a choke point in the Middle East or the Luzon Strait between the
Philippine and South China seas. If a ship were to drag an anchor across the
wrong patch of seabed, billions of people could wake up to find themselves
either completely disconnected from the internet or surfing with dial-up-like
speeds. The three new cables will all come down from the north of Japan,
through the relatively-empty Bering Sea — and the Arctic Ocean, where each of
the cables will run for more than 5,000 miles, is one of the least-trafficked
parts of the world. That said, the cables will still have to be laid hundreds
of meters below the surface to avoid the tails of roving icebergs.
The ROTACS cable path
Each cable will be laid by a pair of ships: an ice breaker that leads the
way, and a cable ship. Until now it has been impossible to lay cables in the
Arctic Ocean, but the retreat of the Arctic sea ice means that the Northwest
Passage is now generally ice-free from August to October; a big enough window
that cable can be laid fairly safely. Existing cable ships (and there aren’t
many of them) are all outfitted for balmier climes, so all three cables will
require the use of a polar ice-rated ship that has been retrofitted to carry
cable-laying gear.
Read more about the secret world of submarine cables.
For more information on the Russian Optical Trans-Arctic Submarine Cable
System (ROTACS), check out the Polarnet Project (machine translated).
The Arctic Fibre and Arctic Link websites have information on the North
American cables.
[Image credit: New Scientist]
23
35
Curious that so many routers owned by the same US company would all be
timing out on havanatimes.org with the server located in a former
eastern bloc nation. Oh well, it's back now. Cold war over.
On Sat, Mar 24, 2012 at 5:36 PM, Jeff Tantsura
<jeff.tantsura(a)ericsson.com> wrote:
> 81.169.144 belongs to a German company based in Berlin :)
>
> Regards,
> Jeff
>
> On Mar 24, 2012, at 13:39, "Randy Bush" <randy(a)psg.com> wrote:
>
>> 81.169.145.156
>
1
0
Reports from around the country are that traceroutes through sbcglobal
(in Austin, Houston and NJ) are failing with timeout to
havanatimes.org -- yet when we go in through TOR or Comcast or using
overseas services, their routing is just fine. What gives?
5
5