CVE-2009-0636
published 2009-03-27CVE-2009-0636: Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device…
high7.8CVSS 3.1
AVNACLAuNCNINAC
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message.
Affected
311 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2009-03-25·CVSS 7.8
CVE-2009-0636 [HIGH] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability exists in the Session Initiation Protocol (SIP)
implementation in Cisco IOS Software that can be exploited remotely to cause a
reload of the Cisco IOS device.
Cisco has released software updates that address this vulnerability. There are no workarounds available to mitigate the vulnerability
apart from disabling SIP, if the Cisco IOS device does not need to run SIP for
VoIP services. However, mitigation techniques are available to help limit
exposure to the vulnerability.
This advisory is posted at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090325-sip.
Note: The March 25, 2009, Cisco IOS Security Advisory bundled publication
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco
CVE-2009-0636 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
CVE-2009-0636: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability exists in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software that can be exploited remotely to cause a reload of the Cisco IOS device. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsu11522, CSCsb25337, CSCsu11522, CSCsu11522, CSCsk64158
GHSA
GHSA-hvr2-xgj6-r6c3: Unspecified vulnerability in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-0636 [HIGH] GHSA-hvr2-xgj6-r6c3: Unspecified vulnerability in Cisco IOS 12
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34438http://securitytracker.com/id?1021902http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c0.shtmlhttp://www.securityfocus.com/bid/34243http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49421http://secunia.com/advisories/34438http://securitytracker.com/id?1021902http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c0.shtmlhttp://www.securityfocus.com/bid/34243http://www.vupen.com/english/advisories/2009/0851https://exchange.xforce.ibmcloud.com/vulnerabilities/49421
2009-03-27
Published