CVE-2011-4667 describes a vulnerability in the encryption libraries of specific versions of Cisco IOS and NX-OS software, impacting devices like the Cisco MDS 9222i, MDS 9000 modules, and VPN Services Port Adaptor, when IP Security (IPSec) is in use. This medium-severity vulnerability (CVSS 5.9) allows remote attackers, with high attack complexity, to intercept and obtain unencrypted packets from otherwise encrypted sessions, leading to a high confidentiality impact. Despite its potential for data exposure, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(33\)sxiCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sxi:*:*:*:*:*:*:* | ||
12.2\(33\)sxjCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sxj:*:*:*:*:*:*:* | ||
15.2\(1\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(1\)t:*:*:*:*:*:*:* | ||
15.2\(1\)t1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(1\)t1:*:*:*:*:*:*:* | ||
15.2\(2\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)t:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.