Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2871


Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002.


Published

2009-09-28T19:30:01.517

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.2xna Yes
Operating System cisco ios 12.2xnb Yes
Operating System cisco ios 12.2xnc Yes
Operating System cisco ios 12.2xnd Yes
Operating System cisco ios 12.4md Yes
Operating System cisco ios 12.4mr Yes
Operating System cisco ios 12.4sw Yes
Operating System cisco ios 12.4t Yes
Operating System cisco ios 12.4xf Yes
Operating System cisco ios 12.4xj Yes
Operating System cisco ios 12.4xk Yes
Operating System cisco ios 12.4xq Yes
Operating System cisco ios 12.4xr Yes
Operating System cisco ios 12.4xv Yes
Operating System cisco ios 12.4xw Yes
Operating System cisco ios 12.4xy Yes
Operating System cisco ios 12.4xz Yes

References