CVE-2009-2868 - CVE House
Back to Database
Status published High CVE-2009-2868

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based...

Vulnerability Description

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2868

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ios
Vulnerable Versions:
12.2ex, 12.2ira, 12.2irb, 12.2irc, 12.2sb, 12.2sca, 12.2scb, 12.2se, 12.2sra, 12.2srb, 12.2src, 12.2srd, 12.2sxh, 12.2sxi, 12.2xna, 12.2xnb, 12.2xnc, 12.2xnd, 12.3t, 12.3xl, 12.3xr, 12.3xs, 12.3xx, 12.3ya, 12.3yd, 12.3yf, 12.3yg, 12.3yh, 12.3yi, 12.3yq, 12.3ys, 12.3yt, 12.3yu, 12.3yx, 12.3yz, 12.4, 12.4t, 12.4xb, 12.4xc, 12.4xd

Timeline

Official Publish: September 28th, 2009
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.