QID 317438
QID 317438: Cisco Internetwork Operating System (IOS) and Internetwork Operating System (IOS) XE Software Internet Key Exchange Version 1 Fragmentation Denial of Service (DoS) Vulnerabilities (cisco-sa-ikev1-NO2ccFWz)
Multiple vulnerabilities in the Internet Key Exchange version 1 (IKEv1) fragmentation feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow or corruption on an affected system.
Affected Products:
Cisco IOS or IOS XE Software and both of the following conditions are true:
IKEv1 fragmentation is enabled
Any type of VPN that is based on IKEv1 is configured
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow an unauthenticated, remote attacker to cause a heap overflow or corruption on an affected system.
Customers are advised to refer to cisco-sa-ikev1-NO2ccFWz for more information.
- cisco-sa-ikev1-NO2ccFWz -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ikev1-NO2ccFWz
CVEs related to QID 317438
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ikev1-NO2ccFWz |
|