CVE-2008-3798 describes a denial-of-service vulnerability in Cisco IOS 12.4, where a remote attacker can crash a device by sending a normal SSL packet during session termination. This vulnerability has a high severity CVSS score of 7.8, indicating it can be exploited remotely with low complexity and no authentication, leading to a complete loss of availability. Despite its age, there is no known public exploit code, Metasploit modules, or significant community discussion or media coverage, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:* | ||
12.4mrCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.4mr:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.