First published: Thu Mar 25 2010(Updated: )
The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service (device reload) via a malformed IKE packet, aka Bug ID CSCtb13491.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.2sb | |
Cisco IOS | =12.2sca | |
Cisco IOS | =12.2scb | |
Cisco IOS | =12.2scc | |
Cisco IOS | =12.2sra | |
Cisco IOS | =12.3t | |
Cisco IOS | =12.3xe | |
Cisco IOS | =12.3xj | |
Cisco IOS | =12.3xr | |
Cisco IOS | =12.3xu | |
Cisco IOS | =12.3xw | |
Cisco IOS | =12.3xx | |
Cisco IOS | =12.3yf | |
Cisco IOS | =12.3yg | |
Cisco IOS | =12.3yk | |
Cisco IOS | =12.3yq | |
Cisco IOS | =12.3ys | |
Cisco IOS | =12.3yu | |
Cisco IOS | =12.3yx | |
Cisco IOS | =12.3za | |
Cisco IOS | =12.4 | |
Cisco IOS | =12.4gc | |
Cisco IOS | =12.4ja | |
Cisco IOS | =12.4jda | |
Cisco IOS | =12.4jdc | |
Cisco IOS | =12.4jdd | |
Cisco IOS | =12.4jk | |
Cisco IOS | =12.4jl | |
Cisco IOS | =12.4jma | |
Cisco IOS | =12.4jmb | |
Cisco IOS | =12.4jx | |
Cisco IOS | =12.4md | |
Cisco IOS | =12.4mda | |
Cisco IOS | =12.4mr | |
Cisco IOS | =12.4sw | |
Cisco IOS | =12.4t | |
Cisco IOS | =12.4xa | |
Cisco IOS | =12.4xb | |
Cisco IOS | =12.4xc | |
Cisco IOS | =12.4xd | |
Cisco IOS | =12.4xe | |
Cisco IOS | =12.4xf | |
Cisco IOS | =12.4xg | |
Cisco IOS | =12.4xj | |
Cisco IOS | =12.4xk | |
Cisco IOS | =12.4xl | |
Cisco IOS | =12.4xm | |
Cisco IOS | =12.4xn | |
Cisco IOS | =12.4xp | |
Cisco IOS | =12.4xq | |
Cisco IOS | =12.4xr | |
Cisco IOS | =12.4xt | |
Cisco IOS | =12.4xv | |
Cisco IOS | =12.4xw | |
Cisco IOS | =12.4xy | |
Cisco IOS | =12.4xz | |
Cisco IOS | =12.4ya | |
Cisco IOS | =12.4yb | |
Cisco IOS | =12.4yd | |
Cisco IOS | =12.4ye | |
Cisco IOS | =12.4yg | |
Cisco 7200 | ||
Cisco 7301 Router | ||
Cisco 7200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0578 is classified as a high severity vulnerability due to its potential to cause a denial of service on affected Cisco routers.
To fix CVE-2010-0578, upgrade the Cisco IOS to a version that is not vulnerable, as specified in the security advisory.
CVE-2010-0578 affects Cisco IOS versions 12.2 through 12.4 running on Cisco 7200 and 7301 routers.
Exploitation of CVE-2010-0578 can lead to remote attackers causing the affected device to reload, resulting in service disruption.
Yes, CVE-2010-0578 can be exploited remotely by sending a malformed IKE packet to the vulnerable device.