CVE-2009-0626
published 2009-03-27CVE-2009-0626: The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.97%
78.3th percentile
The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
vendor_cisco·2009-03-25·CVSS 7.8
CVE-2009-0626 [HIGH] CWE-399 Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
Cisco IOS software contains two vulnerabilities within the Cisco IOS
WebVPN or Cisco IOS SSLVPN feature (SSLVPN) that can be remotely exploited
without authentication to cause a denial of service condition. Both
vulnerabilities affect both Cisco IOS WebVPN and Cisco IOS SSLVPN
features:
Crafted HTTPS packet will crash device.
SSLVPN sessions cause a memory leak in the device.
Cisco has released software updates that address these vulnerabilities.
There are no workarounds that mitigate these vulnerabilities.
This advisory is posted at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090325-webvpn.
Note: The March 25, 2009, Cisco IOS Security Advisory bundled publication
Cisco
Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
vendor_cisco
CVE-2009-0626 Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
CVE-2009-0626: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
Cisco IOS software contains two vulnerabilities within the Cisco IOS WebVPN or Cisco IOS SSLVPN feature (SSLVPN) that can be remotely exploited without authentication to cause a denial of service condition. Both vulnerabilities affect both Cisco IOS WebVPN and Cisco IOS SSLVPN features: Crafted HTTPS packet will crash device. SSLVPN sessions cause a memory leak in the device. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsl30548, CSCsx15333, CSCsx28406, CSCsl30548, CSCsx15333
GHSA
GHSA-mh9q-4hwx-prrv: The SSLVPN feature in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-0626 [HIGH] GHSA-mh9q-4hwx-prrv: The SSLVPN feature in Cisco IOS 12
The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34438http://securitytracker.com/id?1021896http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90424.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.securityfocus.com/bid/34239http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49425https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6919http://secunia.com/advisories/34438http://securitytracker.com/id?1021896http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90424.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.securityfocus.com/bid/34239http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49425https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6919
2009-03-27
Published