PT-2009-5225 · Cisco · Cisco Ios
Published
2009-09-23
·
Updated
2017-09-19
·
CVE-2009-2867
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.2XNA through 12.2XND
Cisco IOS versions 12.4T
Cisco IOS versions 12.4XZ
Cisco IOS versions 12.4YA
Description
The issue allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet when Zone-Based Policy Firewall SIP Inspection is enabled. Exploitation of the issue could result in a reload of the affected device.
Recommendations
For Cisco IOS versions 12.2XNA through 12.2XND, update to a version that includes the fix for this issue.
For Cisco IOS versions 12.4T, update to a version that includes the fix for this issue.
For Cisco IOS versions 12.4XZ, update to a version that includes the fix for this issue.
For Cisco IOS versions 12.4YA, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the SIP inspection feature in the Zone-Based Policy Firewall until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios