CVE-2009-0631: High severity Cisco IOS vulnerability
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) allows remote attackers to cause a denial of service (blocked input queue on the inbound interface) via a crafted UDP packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the IP Service Level Agreements (SLAs) Responder feature on affected Cisco IOS devices to mitigate the denial-of-service condition caused by crafted UDP packets.
Cisco IOS IP Service Level Agreements (SLAs) Responder enabled = disabled - Configuration
Disable Session Initiation Protocol (SIP) support on affected Cisco IOS devices if it is not required, to mitigate the denial-of-service condition caused by crafted UDP packets.
Cisco IOS Session Initiation Protocol (SIP) enabled = disabled - Configuration
Disable H.323 Annex E Call Signaling Transport on affected Cisco IOS devices if it is not required, to mitigate the denial-of-service condition caused by crafted UDP packets.
Cisco IOS H.323 Annex E Call Signaling Transport enabled = disabled - Configuration
Disable Media Gateway Control Protocol (MGCP) support on affected Cisco IOS devices if it is not required, to mitigate the denial-of-service condition caused by crafted UDP packets.
Cisco IOS Media Gateway Control Protocol (MGCP) enabled = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0631?
CVE-2009-0631 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2009-0631?
To fix CVE-2009-0631, you should upgrade to a non-vulnerable version of Cisco IOS.
What types of configurations are affected by CVE-2009-0631?
CVE-2009-0631 affects Cisco IOS versions when configured with IP SLAs Responder, SIP, H.323 Annex E, or MGCP.
Can CVE-2009-0631 be exploited remotely?
Yes, CVE-2009-0631 can be exploited remotely by attackers, potentially leading to a denial of service.
What Cisco IOS versions are vulnerable to CVE-2009-0631?
CVE-2009-0631 affects Cisco IOS versions 12.0 through 12.4.