Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-2836


Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is enabled, allows remote attackers to cause a denial of service (memory consumption) by improperly disconnecting SSL sessions, leading to connections that remain in the CLOSE-WAIT state, aka Bug ID CSCtg21685.


Published

2010-09-23T19:00:13.980

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.4 Yes
Operating System cisco ios 12.4gc Yes
Operating System cisco ios 12.4mda Yes
Operating System cisco ios 12.4mr Yes
Operating System cisco ios 12.4mra Yes
Operating System cisco ios 12.4sw Yes
Operating System cisco ios 12.4xa Yes
Operating System cisco ios 12.4xb Yes
Operating System cisco ios 12.4xc Yes
Operating System cisco ios 12.4xd Yes
Operating System cisco ios 12.4xe Yes
Operating System cisco ios 12.4xf Yes
Operating System cisco ios 12.4xg Yes
Operating System cisco ios 12.4xj Yes
Operating System cisco ios 12.4xk Yes
Operating System cisco ios 12.4xl Yes
Operating System cisco ios 12.4xm Yes
Operating System cisco ios 12.4xn Yes
Operating System cisco ios 12.4xp Yes
Operating System cisco ios 12.4xt Yes
Operating System cisco ios 12.4xv Yes
Operating System cisco ios 12.4xw Yes
Operating System cisco ios 12.4xy Yes
Operating System cisco ios 12.4xz Yes
Operating System cisco ios 12.4ya Yes
Operating System cisco ios 12.4yb Yes
Operating System cisco ios 12.4yd Yes
Operating System cisco ios 15.0m Yes
Operating System cisco ios 15.0xa Yes
Operating System cisco ios 15.1\(1\)xb1 Yes
Operating System cisco ios 15.1t Yes

References