Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
BID:36497
Info
Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
| Bugtraq ID: | 36497 |
| Class: | Design Error |
| CVE: |
CVE-2009-2868 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2009 12:00AM |
| Updated: | Oct 20 2009 03:38PM |
| Credit: | Cisco |
| Vulnerable: |
Cisco IOS XE 2.2.3 Cisco IOS XE 2.2 Cisco IOS XE 2.1 Cisco IOS 12.4XD Cisco IOS 12.4XC Cisco IOS 12.4XB Cisco IOS 12.4XA Cisco IOS 12.4T Cisco IOS 12.4 Cisco IOS 12.3YZ Cisco IOS 12.3YX Cisco IOS 12.3YU Cisco IOS 12.3YT Cisco IOS 12.3YS Cisco IOS 12.3YQ Cisco IOS 12.3YK Cisco IOS 12.3YI Cisco IOS 12.3YH Cisco IOS 12.3YG Cisco IOS 12.3YF Cisco IOS 12.3YD Cisco IOS 12.3YA Cisco IOS 12.3XX Cisco IOS 12.3XS Cisco IOS 12.3XR Cisco IOS 12.3XL Cisco IOS 12.3T Cisco IOS 12.2XND Cisco IOS 12.2XNC Cisco IOS 12.2XNB Cisco IOS 12.2XNA Cisco IOS 12.2SXI Cisco IOS 12.2SXH Cisco IOS 12.2SRD Cisco IOS 12.2SRC Cisco IOS 12.2SRB Cisco IOS 12.2SRA Cisco IOS 12.2SE Cisco IOS 12.2SCB Cisco IOS 12.2SCA Cisco IOS 12.2SB Cisco IOS 12.2IRC Cisco IOS 12.2IRB Cisco IOS 12.2IRA Cisco IOS 12.2EX Cisco IOS 12.2(33)SXH5 Cisco IOS 12.2(33)SXH4 Cisco IOS 12.2(33)SXH3 |
| Not Vulnerable: |
Cisco IOS XE 2.3.1 t Cisco IOS 12.4XN Cisco IOS 12.4(9)T Cisco IOS 12.4(7) Cisco IOS 12.4(6)T1 Cisco IOS 12.4(4)T8 Cisco IOS 12.3(8)T11 Cisco IOS 12.2(52)SE Cisco IOS 12.2(50)SE3 Cisco IOS 12.2(44)EX Cisco IOS 12.2(33)SXI2a Cisco IOS 12.2(33)SXH6 Cisco IOS 12.2(33)SRD3 Cisco IOS 12.2(33)SRD2a Cisco IOS 12.2(33)SRC5 Cisco IOS 12.2(33)SCB4 Cisco IOS 12.2(33)SB6 |
Discussion
Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to consume all available Phase 1 security associations, which may prevent new IPSec sessions from being established.
This issue is being tracked by Cisco Bug IDs CSCsy07555 and CSCee72997.
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to consume all available Phase 1 security associations, which may prevent new IPSec sessions from being established.
This issue is being tracked by Cisco Bug IDs CSCsy07555 and CSCee72997.
Exploit / POC
Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial of Service Vulnerability
References:
References:
- Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of th (Cisco)
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Cisco IOS Software Internet Key Exchange Resource Exhau (Cisco)
- Cisco Security Advisory: Cisco IOS Software Internet Key Exchange Resource Exhau (Cisco)
- Summary of Cisco IOS Software Bundled Advisories, September 23, 2009 (Cisco)