CVE-2009-2871: High severity cisco ios vulnerability
Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2871?
CVE-2009-2871 has a high severity as it allows remote attackers to cause a denial of service through crafted encrypted packets.
How do I fix CVE-2009-2871?
To fix CVE-2009-2871, upgrade to a patched version of Cisco IOS that mitigates this vulnerability.
Which Cisco IOS versions are affected by CVE-2009-2871?
CVE-2009-2871 affects Cisco IOS versions 12.2xnd and 12.4t, including various specific releases under 12.4.
Can CVE-2009-2871 be exploited easily?
Yes, CVE-2009-2871 can potentially be exploited easily by remote attackers with the right crafted packets.
What type of denial of service does CVE-2009-2871 cause?
CVE-2009-2871 can cause a device reload, resulting in a temporary denial of service.