CVE-2009-0636: High severity Cisco IOS vulnerability
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable SIP voice services on affected Cisco IOS devices (the vulnerability occurs when SIP voice services are enabled).
Cisco IOS SIP voice services = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0636?
CVE-2009-0636 is considered to have a high severity level due to the risk of a denial of service attack that can crash Cisco devices.
How do I fix CVE-2009-0636?
To fix CVE-2009-0636, upgrade the affected Cisco IOS versions to a patched version that addresses the vulnerability.
Which Cisco IOS versions are affected by CVE-2009-0636?
CVE-2009-0636 affects Cisco IOS versions from 12.0 through 12.4 when SIP voice services are enabled.
Can CVE-2009-0636 be exploited remotely?
Yes, CVE-2009-0636 can be exploited remotely by sending a valid SIP message to the affected device.
What types of devices are impacted by CVE-2009-0636?
Devices running affected versions of Cisco IOS with SIP voice services enabled are susceptible to CVE-2009-0636.