CVE-2009-2868: High severity cisco ios vulnerability
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2868?
CVE-2009-2868 is categorized as a denial of service vulnerability affecting certain versions of Cisco IOS.
How do I fix CVE-2009-2868?
To mitigate CVE-2009-2868, upgrade to a version of Cisco IOS that is not affected by this vulnerability, as specified in Cisco's security advisories.
Who is affected by CVE-2009-2868?
CVE-2009-2868 affects remote attackers targeting Cisco IOS versions 12.2 through 12.4 with certificate-based authentication enabled for IKE.
What kind of attack is possible with CVE-2009-2868?
CVE-2009-2868 allows attackers to cause Phase 1 SA exhaustion, leading to a denial of service condition.
Is there a workaround for CVE-2009-2868?
Currently, Cisco recommends upgrading to fixed software versions as the primary solution for CVE-2009-2868.