CVE-2009-0629
published 2009-03-27CVE-2009-0629: The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture…
PriorityP430medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
4.03%
89.5th percentile
The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets.
Affected
191 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8pm-776c-452x: Cisco IOS 12
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2011-1625 [MEDIUM] CWE-362 GHSA-v8pm-776c-452x: Cisco IOS 12
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka Bug ID CSCtf74999, a different vulnerability than CVE-2007-0199, CVE-2008-1152, and CVE-2009-0629.
GHSA
GHSA-x6xf-5q35-j8vr: The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Archi
ghsa_unreviewed·2022-05-02
CVE-2009-0629 [MEDIUM] GHSA-x6xf-5q35-j8vr: The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Archi
The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets.
Cisco
Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
vendor_cisco·2009-03-25·CVSS 7.8
CVE-2009-0629 [HIGH] CWE-399 Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
Cisco IOS® Software contains a vulnerability
in multiple features that could allow an attacker to cause a denial of service
(DoS) condition on the affected device. A sequence of specially crafted TCP
packets can cause the vulnerable device to reload.
Cisco has released software updates that address this vulnerability.
Several mitigation strategies are outlined in the workarounds section
of this advisory.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090325-tcp.
Note: The March 25, 2009, Cisco IOS Security Advisory bundled publication
includes eight Security Advisories. All of the advisories address
vulnerabilities in Cisco IOS Software. Each advis
Cisco
Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
vendor_cisco
CVE-2009-0629 Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
CVE-2009-0629: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
Cisco IOS � Software contains a vulnerability in multiple features that could allow an attacker to cause a denial of service (DoS) condition on the affected device. A sequence of specially crafted TCP packets can cause the vulnerable device to reload. Cisco has released software updates that address this vulnerability. Several mitigation strategies are outlined in the
CWE: CWE-399, CWE-399
Bug IDs: CSCsr29468, CSCsr29468
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34438http://securitytracker.com/id?1021903http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904cb.shtmlhttp://www.securityfocus.com/bid/34238http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49420http://secunia.com/advisories/34438http://securitytracker.com/id?1021903http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904cb.shtmlhttp://www.securityfocus.com/bid/34238http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49420
2009-03-27
Published