CVE-2012-5017: Cisco Asr 1001
Medium severity, CVSS 6.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
Affected products
- Cisco Asr 1001
- Cisco Asr 1002
- Cisco Asr 1002-X
- Cisco Asr 1002 Fixed Router
- Cisco Asr 1004
- Cisco Asr 1006
- Cisco Asr 1023 Router
- Cisco IOS: up to and including 15.1\(1\)sy; version 15.1 only
Published 2014-04-23. Last modified 2026-06-16.