Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
BID:36502
Info
Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
| Bugtraq ID: | 36502 |
| Class: | Unknown |
| CVE: |
CVE-2009-2869 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2009 12:00AM |
| Updated: | Sep 23 2009 07:30PM |
| Credit: | Cisco |
| Vulnerable: |
Cisco IOS 12.4YE Cisco IOS 12.4YD Cisco IOS 12.4YA Cisco IOS 12.4XZ Cisco IOS 12.4T Cisco IOS 12.4MD |
| Not Vulnerable: |
Cisco IOS 12.4(24)T Cisco IOS 12.4(22)YE1 Cisco IOS 12.4(22)YD1 Cisco IOS 12.4(22)T Cisco IOS 12.4(22)MD Cisco IOS 12.4(20)T |
Discussion
Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug IDs CSCsu24505 and CSCsv75948.
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug IDs CSCsu24505 and CSCsv75948.
Exploit / POC
Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Cisco IOS Software Network Time Protocol Packet Vulnera (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco IOS Software Network Time Protocol Packet Vulnera (Cisco)