CVE-2009-0635
published 2009-03-27CVE-2009-0635: Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows…
high7.1CVSS 3.1
AVNACMAuNCNINAC
Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_ctcp | — | — |
Cisco
Cisco IOS cTCP Denial of Service Vulnerability
vendor_cisco·2009-03-25·CVSS 7.8
CVE-2009-0635 [HIGH] CWE-399 Cisco IOS cTCP Denial of Service Vulnerability
Cisco IOS cTCP Denial of Service Vulnerability
A series of TCP packets may cause a denial of service (DoS) condition
on Cisco IOS devices that are configured as Easy VPN servers with the Cisco
Tunneling Control Protocol (cTCP) encapsulation feature. Cisco has released software updates that address this vulnerability. No workarounds are
available; however, the IPSec NAT traversal (NAT-T) feature can be used as an
alternative.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090325-ctcp.
Note: The March 25, 2009, Cisco IOS Security Advisory
bundled publication includes eight Security Advisories. All of the advisories
address vulnerabilities in Cisco IOS Software. Each advisory lists the releases
that correct the vulnerab
Cisco
Cisco IOS cTCP Denial of Service Vulnerability
vendor_cisco
CVE-2009-0635 Cisco IOS cTCP Denial of Service Vulnerability
CVE-2009-0635: Cisco IOS cTCP Denial of Service Vulnerability
A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers with the Cisco Tunneling Control Protocol (cTCP) encapsulation feature. Cisco has released software updates that address this vulnerability. No
CWE: CWE-399, CWE-399
Bug IDs: CSCsr16693, CSCsu21828, CSCsr16693, CSCsu21828
GHSA
GHSA-jrx8-5mjp-vjpm: Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-0635 [HIGH] GHSA-jrx8-5mjp-vjpm: Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12
Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34438http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90459.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.securityfocus.com/bid/34246http://www.securitytracker.com/id?1021895http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49417http://secunia.com/advisories/34438http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90459.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.securityfocus.com/bid/34246http://www.securitytracker.com/id?1021895http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49417
2009-03-27
Published