CVE-2009-0630
published 2009-03-27CVE-2009-0630: The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and…
high7.1CVSS 3.1
AVNACMAuNCNINAC
The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7) Distributed Director with HTTP Redirects; and (8) TCP DNS features in Cisco IOS 12.0 through 12.4 do not properly handle IP sockets, which allows remote attackers to cause a denial of service (outage or resource consumption) via a series of crafted TCP packets.
Affected
311 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Cisco
Cisco IOS Software Multiple Features IP Sockets Vulnerability
vendor_cisco·2009-03-25·CVSS 7.8
CVE-2009-0630 [HIGH] CWE-399 Cisco IOS Software Multiple Features IP Sockets Vulnerability
Cisco IOS Software Multiple Features IP Sockets Vulnerability
A vulnerability in the handling of IP sockets can cause devices to be
vulnerable to a denial of service attack when any of several features of Cisco
IOS? Software are enabled. A sequence of specially
crafted TCP/IP packets could cause any of the following results:
The configured feature may stop accepting new connections or
sessions.
The memory of the device may be consumed.
The device may experience prolonged high CPU utilization.
The device may reload.
Cisco has released software updates that address this vulnerability.
Several mitigation strategies are outlined in the "Workarounds" section
of this advisory.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa
Cisco
Cisco IOS Software Multiple Features IP Sockets Vulnerability
vendor_cisco
CVE-2009-0630 Cisco IOS Software Multiple Features IP Sockets Vulnerability
CVE-2009-0630: Cisco IOS Software Multiple Features IP Sockets Vulnerability
A vulnerability in the handling of IP sockets can cause devices to be vulnerable to a denial of service attack when any of several features of Cisco IOS ? Software are enabled. A sequence of specially crafted TCP/IP packets could cause any of the following results: The configured feature may stop accepting new connections or sessions. The memory of the device may be consumed. The device may experience prolonged high CPU utilization. The device may reload. Cisco has released software updates that address this vulnerability. Several mitigation strategies are outlined in the "
CWE: CWE-399, CWE-399
Bug IDs: CSCsm27071, CSCsm27071
GHSA
GHSA-jc4c-fgp6-8m4x: The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Sign
ghsa_unreviewed·2022-05-02
CVE-2009-0630 [HIGH] GHSA-jc4c-fgp6-8m4x: The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Sign
The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7) Distributed Director with HTTP Redirects; and (8) TCP DNS features in Cisco IOS 12.0 through 12.4 do not properly handle IP sockets, which allows remote attackers to cause a denial of service (outage or resource consumption) via a series of crafted TCP packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34438http://securitytracker.com/id?1021897http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c6.shtmlhttp://www.securityfocus.com/bid/34242http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49418http://secunia.com/advisories/34438http://securitytracker.com/id?1021897http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c6.shtmlhttp://www.securityfocus.com/bid/34242http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49418
2009-03-27
Published