First published: Tue Jun 29 2010(Updated: )
Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASA 5580 | <=8.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4918 is classified with a moderate severity due to its potential to cause denial of service.
To fix CVE-2009-4918, upgrade to Cisco ASA software version 8.1(2) or later.
CVE-2009-4918 affects Cisco Adaptive Security Appliances (ASA) 5580 series running software before version 8.1(2).
CVE-2009-4918 allows remote attackers to perform a denial of service by sending malformed NAT-T packets.
NAT-T (Network Address Translation Traversal) packets are used in IPsec IPSec VPN to negotiate a secure tunnel, and malformed packets can exploit this vulnerability.