CVE-2009-2868: High severity cisco ios vulnerability

Published Sep 28, 2009
·
Updated

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

Affected Software

40 affected components
Cisco IOS=12.2xnd
Cisco IOS=12.3yq
Cisco IOS=12.3xr
Cisco IOS=12.4t
Cisco IOS=12.3ya
Cisco IOS=12.2irc
Cisco IOS=12.2scb
Cisco IOS=12.3xs
Cisco IOS=12.2srb
Cisco IOS=12.2xna
Cisco IOS=12.3yu
Cisco IOS=12.3t
Cisco IOS=12.2sca
Cisco IOS=12.3yd
Cisco IOS=12.2ex
Cisco IOS=12.2ira
Cisco IOS=12.3xl
Cisco IOS=12.2se
Cisco IOS=12.2sxh
Cisco IOS=12.3yf
Cisco IOS=12.4xd
Cisco IOS=12.2sb
Cisco IOS=12.3yt
Cisco IOS=12.3yz
Cisco IOS=12.3yg
Cisco IOS=12.4
Cisco IOS=12.2srd
Cisco IOS=12.2xnb
Cisco IOS=12.2sxi
Cisco IOS=12.3yx
Cisco IOS=12.3ys
Cisco IOS=12.2sra
Cisco IOS=12.2irb
Cisco IOS=12.3yh
Cisco IOS=12.4xb
Cisco IOS=12.3xx
Cisco IOS=12.2xnc
Cisco IOS=12.4xc
Cisco IOS=12.3yi
Cisco IOS=12.2src

Event History

Sep 28, 2009
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2009-2868?

CVE-2009-2868 is categorized as a denial of service vulnerability affecting certain versions of Cisco IOS.

2

How do I fix CVE-2009-2868?

To mitigate CVE-2009-2868, upgrade to a version of Cisco IOS that is not affected by this vulnerability, as specified in Cisco's security advisories.

3

Who is affected by CVE-2009-2868?

CVE-2009-2868 affects remote attackers targeting Cisco IOS versions 12.2 through 12.4 with certificate-based authentication enabled for IKE.

4

What kind of attack is possible with CVE-2009-2868?

CVE-2009-2868 allows attackers to cause Phase 1 SA exhaustion, leading to a denial of service condition.

5

Is there a workaround for CVE-2009-2868?

Currently, Cisco recommends upgrading to fixed software versions as the primary solution for CVE-2009-2868.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203