PT-2009-5230 · Cisco · Cisco Ios

Publicado

2009-09-23

·

Atualizado

2009-10-01

·

CVE-2009-2872

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco IOS versions 12.0 through 12.4
Description: The issue allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel when IP-based tunnels and the Cisco Express Forwarding feature are enabled. Cisco devices running affected versions of Cisco IOS Software are vulnerable to a denial of service (DoS) attack if configured for IP tunnels and Cisco Express Forwarding.
Recommendations: For Cisco IOS versions 12.0 through 12.4, update to a version that includes the software updates released by Cisco to address this issue. As a temporary workaround, consider disabling the IP-based tunnels and the Cisco Express Forwarding feature until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2872

Produtos afetados

Cisco Ios