CVE-2009-2868
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2009
Last modified:
09/04/2025
Description
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios:12.2ex:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2ira:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2irb:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2irc:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2sb:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2sca:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2scb:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2se:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2sra:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2srb:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2src:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2srd:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2sxh:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2sxi:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios:12.2xna:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://tools.cisco.com/security/center/viewAlert.x?alertId=18887
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8117.shtml
- http://www.vupen.com/english/advisories/2009/2759
- http://tools.cisco.com/security/center/viewAlert.x?alertId=18887
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8117.shtml
- http://www.vupen.com/english/advisories/2009/2759



