CVE-2009-2867
published 2009-09-28CVE-2009-2867: Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is…
high7.8CVSS 3.1
AVNACLAuNCNINAC
Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-6fp8-mc4g-xqxw: Unspecified vulnerability in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-2867 [HIGH] GHSA-6fp8-mc4g-xqxw: Unspecified vulnerability in Cisco IOS 12
Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.
Cisco
Cisco IOS Software Zone-Based Policy Firewall Vulnerability
vendor_cisco·2009-09-23·CVSS 7.8
CVE-2009-2867 [HIGH] CWE-399 Cisco IOS Software Zone-Based Policy Firewall Vulnerability
Cisco IOS Software Zone-Based Policy Firewall Vulnerability
Cisco IOS® devices that are configured with
Cisco IOS Zone-Based Policy Firewall Session Initiation Protocol (SIP)
inspection are vulnerable to denial of service (DoS) attacks when processing a
specific SIP transit packet. Exploitation of the vulnerability could result in
a reload of the affected device.
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are available.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-ios-fw
Note: The September 23, 2009, Cisco IOS Security Advisory bundled
publication includes eleven Security Advisories. Ten of the advisories address
vulnerabilities in Cisco
Cisco
Cisco IOS Software Zone-Based Policy Firewall Vulnerability
vendor_cisco
CVE-2009-2867 Cisco IOS Software Zone-Based Policy Firewall Vulnerability
CVE-2009-2867: Cisco IOS Software Zone-Based Policy Firewall Vulnerability
Cisco IOS � devices that are configured with Cisco IOS Zone-Based Policy Firewall Session Initiation Protocol (SIP) inspection are vulnerable to denial of service (DoS) attacks when processing a specific SIP transit packet. Exploitation of the vulnerability could result in a reload of the affected device. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCsr18691, CSCsr18691
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/viewAlert.x?alertId=18886http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8130.shtmlhttp://www.securitytracker.com/id?1022930http://www.vupen.com/english/advisories/2009/2759https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7254http://tools.cisco.com/security/center/viewAlert.x?alertId=18886http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8130.shtmlhttp://www.securitytracker.com/id?1022930http://www.vupen.com/english/advisories/2009/2759https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7254
2009-09-28
Published