CVE-2009-0627
published 2009-09-08CVE-2009-0627: Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service…
PriorityP430high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.12%
80.0th percentile
Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | <= 4.0 | — |
| cisco | products | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwpp-857g-6hpg: Unspecified vulnerability in Cisco NX-OS before 4
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2009-0627 [HIGH] GHSA-jwpp-857g-6hpg: Unspecified vulnerability in Cisco NX-OS before 4
Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.
Cisco
TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
vendor_cisco
CVE-2009-0627 TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
CVE-2009-0627: TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of a TCP connection, an attacker could force the TCP connection to remain in a long-lived state, possibly indefinitely. If enough TCP connections are forced into a long-lived or indefinite state, resources on a system under attack may be consumed, preventing new TCP connections from being accepted. In some cases, a system reboot may be necessary to recover normal system operation. To exploit these vulnerabilities, an attacker must be able to complete a TCP three-way handshake with a vulnerable system. In additio
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2009-09-08
Published