ID

VAR-200908-0252


CVE

CVE-2009-1154


TITLE

Cisco IOS XR Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2009-002660

DESCRIPTION

Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute. An attacker can exploit this issue to cause the BGP process to crash, creating a denial-of-service condition. This issue is being tracked by Cisco Bug ID CSCtb05382. Cisco IOS is an operating system developed by Cisco in the United States for its network equipment. The number of AS numbers must exceed the full or maximum length of the update message to trigger this vulnerability

Trust: 1.98

sources: NVD: CVE-2009-1154 // JVNDB: JVNDB-2009-002660 // BID: 36092 // VULHUB: VHN-38600

AFFECTED PRODUCTS

vendor:ciscomodel:ios xrscope:eqversion:3.5.4

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.5.3

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.5.2

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.4.3

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.4.2

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.4.1

Trust: 1.9

vendor:ciscomodel:ios xrscope:eqversion:3.4

Trust: 1.9

vendor:ciscomodel:ios xrscope:lteversion:3.8.1

Trust: 1.8

vendor:ciscomodel:ios xrscope:eqversion:3.5

Trust: 1.6

vendor:ciscomodel:ios xrscope:eqversion:3.4.0

Trust: 1.6

vendor:ciscomodel:ios xrscope:eqversion:3.6.0

Trust: 1.6

vendor:ciscomodel:ios xrscope:eqversion:3.7.3

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.7.2

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.7.1

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.6.3

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.6.2

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.6.1

Trust: 1.3

vendor:ciscomodel:ios xrscope:eqversion:3.8.0

Trust: 1.0

vendor:ciscomodel:ios xrscope:eqversion:3.7.0

Trust: 1.0

vendor:ciscomodel:ios xrscope:eqversion:3.8.1

Trust: 0.3

vendor:ciscomodel:ios xrscope:eqversion:3.8

Trust: 0.3

vendor:ciscomodel:ios xrscope:eqversion:3.7

Trust: 0.3

vendor:ciscomodel:ios xrscope:eqversion:3.6

Trust: 0.3

sources: BID: 36092 // JVNDB: JVNDB-2009-002660 // CNNVD: CNNVD-200908-327 // NVD: CVE-2009-1154

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-1154
value: LOW

Trust: 1.0

NVD: CVE-2009-1154
value: LOW

Trust: 0.8

CNNVD: CNNVD-200908-327
value: LOW

Trust: 0.6

VULHUB: VHN-38600
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2009-1154
severity: LOW
baseScore: 3.3
vectorString: AV:N/AC:L/AU:M/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-38600
severity: LOW
baseScore: 3.3
vectorString: AV:N/AC:L/AU:M/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-38600 // JVNDB: JVNDB-2009-002660 // CNNVD: CNNVD-200908-327 // NVD: CVE-2009-1154

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-38600 // JVNDB: JVNDB-2009-002660 // NVD: CVE-2009-1154

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200908-327

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200908-327

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-002660

PATCH

title:cisco-sa-20090818-bgpurl:http://www.cisco.com/warp/public/707/cisco-sa-20090818-bgp.shtml

Trust: 0.8

sources: JVNDB: JVNDB-2009-002660

EXTERNAL IDS

db:NVDid:CVE-2009-1154

Trust: 2.8

db:SECTRACKid:1022756

Trust: 2.5

db:JVNDBid:JVNDB-2009-002660

Trust: 0.8

db:CNNVDid:CNNVD-200908-327

Trust: 0.7

db:CISCOid:20090818 CISCO IOS XR SOFTWARE BORDER GATEWAY PROTOCOL VULNERABILITY

Trust: 0.6

db:BIDid:36092

Trust: 0.4

db:VULHUBid:VHN-38600

Trust: 0.1

sources: VULHUB: VHN-38600 // BID: 36092 // JVNDB: JVNDB-2009-002660 // CNNVD: CNNVD-200908-327 // NVD: CVE-2009-1154

REFERENCES

url:http://securitytracker.com/id?1022756

Trust: 2.5

url:http://www.cisco.com/en/us/products/products_security_advisory09186a0080af150f.shtml

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-1154

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-1154

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-38600 // BID: 36092 // JVNDB: JVNDB-2009-002660 // CNNVD: CNNVD-200908-327 // NVD: CVE-2009-1154

CREDITS

Cisco Security bulletin

Trust: 0.6

sources: CNNVD: CNNVD-200908-327

SOURCES

db:VULHUBid:VHN-38600
db:BIDid:36092
db:JVNDBid:JVNDB-2009-002660
db:CNNVDid:CNNVD-200908-327
db:NVDid:CVE-2009-1154

LAST UPDATE DATE

2024-11-23T22:27:52.360000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38600date:2009-08-21T00:00:00
db:BIDid:36092date:2009-08-24T15:32:00
db:JVNDBid:JVNDB-2009-002660date:2011-06-08T00:00:00
db:CNNVDid:CNNVD-200908-327date:2009-08-21T00:00:00
db:NVDid:CVE-2009-1154date:2024-11-21T01:01:47.580

SOURCES RELEASE DATE

db:VULHUBid:VHN-38600date:2009-08-21T00:00:00
db:BIDid:36092date:2009-08-20T00:00:00
db:JVNDBid:JVNDB-2009-002660date:2011-06-08T00:00:00
db:CNNVDid:CNNVD-200908-327date:2009-08-21T00:00:00
db:NVDid:CVE-2009-1154date:2009-08-21T17:30:00.203