First published: Mon Sep 28 2009(Updated: )
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.2xnd | |
Cisco IOS | =12.3yq | |
Cisco IOS | =12.3xr | |
Cisco IOS | =12.4t | |
Cisco IOS | =12.3ya | |
Cisco IOS | =12.2irc | |
Cisco IOS | =12.2scb | |
Cisco IOS | =12.3xs | |
Cisco IOS | =12.2srb | |
Cisco IOS | =12.2xna | |
Cisco IOS | =12.3yu | |
Cisco IOS | =12.3t | |
Cisco IOS | =12.2sca | |
Cisco IOS | =12.3yd | |
Cisco IOS | =12.2ex | |
Cisco IOS | =12.2ira | |
Cisco IOS | =12.3xl | |
Cisco IOS | =12.2se | |
Cisco IOS | =12.2sxh | |
Cisco IOS | =12.3yf | |
Cisco IOS | =12.4xd | |
Cisco IOS | =12.2sb | |
Cisco IOS | =12.3yt | |
Cisco IOS | =12.3yz | |
Cisco IOS | =12.3yg | |
Cisco IOS | =12.4 | |
Cisco IOS | =12.2srd | |
Cisco IOS | =12.2xnb | |
Cisco IOS | =12.2sxi | |
Cisco IOS | =12.3yx | |
Cisco IOS | =12.3ys | |
Cisco IOS | =12.2sra | |
Cisco IOS | =12.2irb | |
Cisco IOS | =12.3yh | |
Cisco IOS | =12.4xb | |
Cisco IOS | =12.3xx | |
Cisco IOS | =12.2xnc | |
Cisco IOS | =12.4xc | |
Cisco IOS | =12.3yi | |
Cisco IOS | =12.2src |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2868 is categorized as a denial of service vulnerability affecting certain versions of Cisco IOS.
To mitigate CVE-2009-2868, upgrade to a version of Cisco IOS that is not affected by this vulnerability, as specified in Cisco's security advisories.
CVE-2009-2868 affects remote attackers targeting Cisco IOS versions 12.2 through 12.4 with certificate-based authentication enabled for IKE.
CVE-2009-2868 allows attackers to cause Phase 1 SA exhaustion, leading to a denial of service condition.
Currently, Cisco recommends upgrading to fixed software versions as the primary solution for CVE-2009-2868.