Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2867


Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.


Published

2009-09-28T19:30:01.420

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.2xna Yes
Operating System cisco ios 12.2xnb Yes
Operating System cisco ios 12.2xnc Yes
Operating System cisco ios 12.2xnd Yes
Operating System cisco ios 12.4t Yes
Operating System cisco ios 12.4xz Yes
Operating System cisco ios 12.4ya Yes
Operating System cisco ios 12.4yb Yes

References